First published: Mon Dec 24 2018(Updated: )
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | <1.1.7-6941 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-8918 is medium, with a severity value of 5.4.
The affected software for CVE-2018-8918 is Synology Router Manager (SRM) before version 1.1.7-6941.
CVE-2018-8918 allows remote attackers to inject arbitrary web script or HTML via the host parameter in info.cgi, leading to a cross-site scripting (XSS) vulnerability.
To fix CVE-2018-8918, it is recommended to update Synology Router Manager (SRM) to version 1.1.7-6941 or later.
More information about CVE-2018-8918 can be found in the Synology security advisory Synology_SA_18_25.