PT-2026-83027 · Synology · Synology Chat Server
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Synology Chat Server versions prior to 2.4.5-22148
Description
An improper neutralization of input during web page generation, known as Cross-site Scripting (XSS), occurs in the extract domain component. This allows remote authenticated users to read or write restricted files and perform limited denial-of-service attacks in DSM through UI interaction.
Recommendations
Update Synology Chat Server to version 2.4.5-22148 or later.
Fix
DoS
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synology Chat Server