CVE-2018-8917

CVSS 3.0 Score 5.4 of 10 (medium)

Details

Published Dec 24, 2018
Updated: Jan 14, 2025
CWE ID 79

Summary

CVE-2018-8917 is a cross-site scripting (XSS) vulnerability affecting Synology DiskStation Manager (DSM) before version 6.1.6-15266. An attacker can exploit this issue by injecting arbitrary web scripts or HTML code into the info.cgi page through the host parameter. Successful exploitation may result in unauthorized access to user sessions or data, potentially leading to serious security consequences. This vulnerability poses a significant risk and should be addressed by applying the available patch or update as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager

Affected Vendors

  • Synology