Cross-Site Scripting Vulnerability in Synology MailPlus Server
CVE-2017-15890
4.8MEDIUM
What is CVE-2017-15890?
The vulnerable MailPlus Server from Synology, prior to version 1.4.0-0415, is susceptible to a cross-site scripting (XSS) flaw. This issue allows remote authenticated users to inject arbitrary web scripts or HTML into the application via the NAME parameter, potentially resulting in unauthorized actions being taken on behalf of the user or revealing sensitive information.
Affected Version(s)
MailPlus Server before 1.4.0-0415