Synology-SA-17:75 MailPlus Server

Publish Time: 2017-11-24 18:01:45 UTC+8

Last Updated: 2017-12-15 10:41:48 UTC+8

Severity
Moderate
Status
Resolved

Abstract

CVE-2017-15890 allows remote authenticated users to inject arbitrary web scripts and HTML code into a susceptible version of MailPlus Server.

Severity

Affected

  • Products
    • MailPlus Server before 1.4.0-0415
  • Models
    • All Synology models

Description

Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.

Mitigation

None

Update Availability

To fix the security issue, please go to DSM > Package Center and update MailPlus Server to 1.4.0-0415 or above.