CVE-2015-9102
Summary
| CVE | CVE-2015-9102 |
|---|---|
| State | PUBLISHED |
| Assigner | synology |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-30 13:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos. |
Risk And Classification
Primary CVSS: v3.0 5.4 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | CWE-79 Cross Site Scripting (CWE-79)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.4 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Photo Station | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Synology | Photo Station | affected 6.0 | Not specified |
| CNA | Synology | Photo Station | affected 6.3 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fortinet Discovers Synology DSM Photo Station Cross-Site Scripting Vulnerability IV | FortiGuard | af854a3a-2127-422b-91ae-364da2661108 | www.fortiguard.com | Third Party Advisory |
| Fortinet Discovers Synology DSM Photo Station Cross-Site Scripting Vulnerability III | FortiGuard | af854a3a-2127-422b-91ae-364da2661108 | www.fortiguard.com | Third Party Advisory |
| Fortinet Discovers Synology DSM Photo Station Cross-Site Scripting Vulnerability II | FortiGuard | af854a3a-2127-422b-91ae-364da2661108 | www.fortiguard.com | Third Party Advisory |
| Photo Station 6.3-2962 | Synology Inc. | af854a3a-2127-422b-91ae-364da2661108 | www.synology.com | Vendor Advisory |
| Fortinet Discovers Synology DSM Photo Station Cross-Site Scripting Vulnerability I | FortiGuard | af854a3a-2127-422b-91ae-364da2661108 | www.fortiguard.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.