Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attackers to inject arbitrary web script or HTML via the album title.
2017-06-30T13:29:00.253
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | audio_station | 5.1-2541 | Yes |
| Application | synology | audio_station | 5.1-2542 | Yes |
| Application | synology | audio_station | 5.1-2547 | Yes |
| Application | synology | audio_station | 5.1-2549 | Yes |
| Application | synology | audio_station | 5.4-2852 | Yes |
| Application | synology | audio_station | 5.4-2853 | Yes |
| Application | synology | audio_station | 5.4-2855 | Yes |