Skip to main content

Missing Custom Error Page

CVE-2018-8913

Severity High
Score 7.1/10

Summary

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • REQUIRED
  • NONE
  • LOW
  • LOW

CWE-756 - Missing Custom Error Page

The software does not return custom error pages to the user, possibly exposing sensitive information.

References

Advisory Timeline

  • Published