CVE-2017-16766
—CVSS 3.0
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
- Vendors
- synology
- Products
- diskstation manager
- Weakness
- CWE-284, CWE-74
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.