Vulnerability Name: | CVE-2015-9102 (CCN-127994) | ||||||||||||
Assigned: | 2015-11-24 | ||||||||||||
Published: | 2015-11-24 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos. | ||||||||||||
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-9102 Source: MISC Type: Third Party Advisory http://www.fortiguard.com/zeroday/FG-VD-15-103 Source: MISC Type: Third Party Advisory http://www.fortiguard.com/zeroday/FG-VD-15-104 Source: MISC Type: Third Party Advisory http://www.fortiguard.com/zeroday/FG-VD-15-109 Source: MISC Type: Third Party Advisory http://www.fortiguard.com/zeroday/FG-VD-15-112 Source: XF Type: UNKNOWN synology-photostation-cve20159102-xss(127994) Source: CCN Type: Synology Product Security Advisory Photo Station 6.3-2962 Source: CONFIRM Type: Vendor Advisory https://www.synology.com/en-global/support/security/Photo_Station_6_3_2962 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |