Medium severity6.5NVD Advisory· Published Dec 22, 2017· Updated May 13, 2026
CVE-2017-16766
CVE-2017-16766
Description
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
Affected products
1- Synology/DiskStation Manager (DSM)v5Range: before 6.1.4-15217
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.synology.com/en-global/support/security/Synology_SA_17_74nvdVendor Advisory
News mentions
0No linked articles in our index yet.