CVE-2018-8917
CVSS 3.0 Score 5.4 of 10 (medium)
Details
Published Dec 24, 2018
Updated: Jan 14, 2025
CWE ID 79
Summary
CVE-2018-8917 is a cross-site scripting (XSS) vulnerability affecting Synology DiskStation Manager (DSM) before version 6.1.6-15266. An attacker can exploit this issue by injecting arbitrary web scripts or HTML code into the info.cgi page through the host parameter. Successful exploitation may result in unauthorized access to user sessions or data, potentially leading to serious security consequences. This vulnerability poses a significant risk and should be addressed by applying the available patch or update as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
Affected Vendors
- Synology