First published: Tue Jun 05 2018(Updated: )
Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Office | <3.0.3-2143 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8924 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2018-8924, update Synology Office to version 3.0.3-2144 or later.
CVE-2018-8924 affects users of Synology Office versions prior to 3.0.3-2143.
CVE-2018-8924 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2018-8924 can be exploited by remote authenticated users who can upload malicious file names.