Vulnerability Details CVE-2017-11148
Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2017-11148
-
cpe:2.3:a:synology:chat:1.0.0-0126
-
cpe:2.3:a:synology:chat:1.0.0-0127
-
cpe:2.3:a:synology:chat:1.0.2-0158
-
cpe:2.3:a:synology:chat:1.0.2-0159