Medium severity5.4NVD Advisory· Published Jun 30, 2017· Updated May 13, 2026
CVE-2015-9103
CVE-2015-9103
Description
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or (2) file name of attachments.
Affected products
2- Synology/Note Stationv5Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.fortiguard.com/zeroday/FG-VD-15-110nvdThird Party Advisory
- www.fortiguard.com/zeroday/FG-VD-15-111nvdThird Party Advisory
- www.synology.com/en-global/support/security/Note_Station_1_1_0214nvdVendor Advisory
News mentions
0No linked articles in our index yet.