CVE-2015-9102
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded…
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- synology/photo station
- Source
- security@synology.com
References
- http://www.fortiguard.com/zeroday/FG-VD-15-103Third Party Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-104Third Party Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-109Third Party Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-112Third Party Advisory
- https://www.synology.com/en-global/support/security/Photo_Station_6_3_2962Vendor Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-103Third Party Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-104Third Party Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-109Third Party Advisory
- http://www.fortiguard.com/zeroday/FG-VD-15-112Third Party Advisory
- https://www.synology.com/en-global/support/security/Photo_Station_6_3_2962Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.