Synology-SA-17:39 Video Station

Publish Time: 2017-08-10 00:00:00 UTC+8

Last Updated: 2017-08-10 16:27:00 UTC+8

Severity
Moderate
Status
Resolved

Abstract

CVE-2017-9556 allows remote authenticated users to inject arbitrary web scripts or HTML codes into a vulnerable version of Video Station.

Severity

Affected

  • Products
    • Video Station before 2.3.0-1435
  • Models
    • All Synology models

Description

Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter.

Mitigation

None

Update Availability

To fix the security issue, please go to DSM > Package Center and update Video Station to 2.3.0-1435 or above.