CVE-2018-8924: XSS
Published Jun 5, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.
Affected Software
1 affected component
Synology Office<3.0.3-2143
Event History
Jun 5, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8924?
CVE-2018-8924 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2018-8924?
To fix CVE-2018-8924, update Synology Office to version 3.0.3-2144 or later.
3
Who is affected by CVE-2018-8924?
CVE-2018-8924 affects users of Synology Office versions prior to 3.0.3-2143.
4
What type of vulnerability is CVE-2018-8924?
CVE-2018-8924 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2018-8924 be exploited remotely?
Yes, CVE-2018-8924 can be exploited by remote authenticated users who can upload malicious file names.