CVE Database
/

CVE-2017-12072

Back to search

CVE-2017-12072

Published: Dec 20, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.

VendorProductVersions

Synology

Photo Station

affected
before 6.8.0-3456

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now