Cross-Site Scripting Vulnerability in Synology Audio Station
CVE-2015-9104

5.4MEDIUM

Key Information:

Vendor
Synology
Vendor
CVE Published:
30 June 2017

Summary

The Synology Audio Station software is vulnerable to cross-site scripting attacks, allowing remote authenticated users to inject potentially malicious web scripts or HTML content through the manipulation of the album title. This can lead to unauthorized actions or the disclosure of sensitive information when other users access the compromised content.

Affected Version(s)

Audio Station 5.1

Audio Station 5.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.