Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_name, or (3) additional_name parameter.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Synology CardDAV Server Address Book Editor 跨站脚本漏洞
Vulnerability Description
Synology CardDAV Server是群晖科技(Synology)公司的一款用于同步通讯录的应用程序。Address Book Editor是其中的一个通讯录编辑器。 Synology CardDAV Server 6.0.8-0086之前版本中的Address Book Editor存在跨站脚本漏洞。远程攻击者可借助‘family_name’、‘given_name’或‘additional_name’参数利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A