Synology-SA-17:75 MailPlus Server
Publish Time: 2017-11-24 18:01:45 UTC+8
Last Updated: 2017-12-15 10:41:48 UTC+8
- Severity
- Moderate
- Status
- Resolved
Abstract
CVE-2017-15890 allows remote authenticated users to inject arbitrary web scripts and HTML code into a susceptible version of MailPlus Server.
Severity
- Impact: Moderate
- CVSS3 Base Score: 4.8
- CVSS3 Base Metrics: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected
- Products
- MailPlus Server before 1.4.0-0415
- Models
- All Synology models
Description
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
Mitigation
None
Update Availability
To fix the security issue, please go to DSM > Package Center and update MailPlus Server to 1.4.0-0415 or above.