Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Synology Contacts for DSM 安全漏洞
Vulnerability Description
Synology Contacts for DSM是中国群晖(Synology)公司的一个通讯录服务器。 Synology Contacts for DSM存在安全漏洞,该漏洞源于攻击者可绕过访问限制以读取或修改文件。
CVSS Information
N/A
Vulnerability Type
N/A