CVE-2018-8913

HIGH

Synology Web Station <2.1.3-0139 - CSRF

Title source: llm
STIX 2.1

Description

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Details

CWE
CWE-756 CWE-601
Status published
Products (1)
synology/web_station < 2.1.3-0139
Published Apr 01, 2019
Tracked Since Feb 18, 2026