Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Synology
Synology router Manager |
|
CPEs | cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Synology
Synology router Manager |
|
Metrics |
ssvc
|
Mon, 09 Dec 2024 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: synology
Published: 2024-12-09T03:32:53.245Z
Updated: 2024-12-09T15:10:13.708Z
Reserved: 2024-11-20T03:43:14.920Z
Link: CVE-2024-53284

Updated: 2024-12-09T15:05:38.024Z

Status : Received
Published: 2024-12-09T04:15:05.220
Modified: 2024-12-09T04:15:05.220
Link: CVE-2024-53284

No data.