Cross-Site Scripting Vulnerability in Synology Note Station
CVE-2018-8912
6.5MEDIUM
What is CVE-2018-8912?
A cross-site scripting (XSS) vulnerability exists in Synology Note Station prior to version 2.5.1-0844, enabling remote authenticated users to inject arbitrary web scripts or HTML through the 'commit_msg' parameter. This vulnerability may allow attackers to manipulate user sessions, steal sensitive data, or perform actions on behalf of legitimate users.
Affected Version(s)
Note Station < 2.5.1-0844