Security Advisory

CVE-2015-9103

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-06-30 13:00:00
Last updated 2024-09-17 03:07:47
Assigner synology
State PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or (2) file name of attachments.