Synology-SA-17:61 Audio Station

Publish Time: 2017-10-30 15:29:46 UTC+8

Last Updated: 2017-10-30 15:29:46 UTC+8

Severity
Moderate
Status
Resolved

Abstract

CVE-2017-15888 allows remote authenticated users to inject arbitrary web scripts and HTML codes into a vulnerable version of Audio Station.

Severity

Affected

  • Products
    • Audio Station before 6.3.0-3260

Description

Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web script or HTML via the NAME parameter.

Mitigation

None

Update Availability

To fix the security issue, please go to DSM > Package Center and update Audio Station to 6.3.0-3260 or above.