CVE-2015-9103
MEDIUMSynology Note Station < 1.1-0212 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or (2) file name of attachments.
Scores
CVSS v3
5.4
EPSS
0.0025
EPSS Percentile
47.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (3)
synology/note_station
< 1.1-0212
Synology/Note Station
< 1.0
Synology/Note Station
< 1.1
Published
Jun 30, 2017
Tracked Since
Feb 18, 2026