Cross-Site Scripting Vulnerability in Synology Photo Station for DiskStation Manager
CVE-2012-1556
Currently unrated
What is CVE-2012-1556?
An XSS vulnerability exists in Synology Photo Station 5 for DiskStation Manager 3.2-1955 that could be exploited by remote attackers. By manipulating the name parameter in requests to photo/photo_one.php, attackers can inject and execute arbitrary web scripts or HTML. This poses significant risks, including unauthorized access to user credentials and exposure of sensitive information.