Cross-Site Scripting Vulnerability in Synology Photo Station
CVE-2017-16771
6.1MEDIUM
What is CVE-2017-16771?
A cross-site scripting (XSS) vulnerability exists in the Log Viewer of Synology Photo Station, which allows attackers to inject malicious web scripts or HTML content via the username parameter. This flaw can potentially lead to unauthorized script execution in the context of the victim's browser, compromising user data and session integrity.
Affected Version(s)
Photo Station before 6.8.3-3463
Photo Station before 6.3-2971