CVE Published: 30/06/2019 |
CVE Updated: 16/09/2024 |
CVE Year: 2019 Source: synology |
Vendor: Synology |
Product: Note Station Status : PUBLISHED
CVE-2019-11827 Description
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbitrary web script or HTML via the object_id parameter.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L