CVE-2018-8913CWE-756

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL

High · published April 1, 2019

CVSS v3.0
7.1
EPSS
1%
Percentile
64.0
In the wild
Unconfirmed
What it is

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.

The record
Technical detail
CVSS v3.0
7.1 · HIGH
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.01119 · 64.0th percentile
Weakness
CWE-756 · Missing Custom Error Page
Published
2019-04-01T14:23Z
EPSS history
Timeline
  • 01 APR 14:23Z
    Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL
    cvelistv5