CVE-2017-16775 is a clickjacking vulnerability in Synology SSO Server versions prior to 2.1.3-0129, specifically within the SSOOauth.cgi component. This medium-severity vulnerability (CVSS 6.1) allows remote attackers to trick users into unintended actions by embedding the affected application within a malicious frame, potentially leading to limited disclosure of information and modification of data. While the attack complexity is low and no authentication is required, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.3-0129CPE matchmatch criteria | cpe:2.3:a:synology:sso_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.