在 Synology Chat Server 2.4.5-22148 之前的版本中,由于在生成网页时未正确中和输入数据(即存在“跨站脚本”漏洞),允许远程已认证用户通过 UI 交互读取或写入任意文件,并可在 DSM 中发起拒绝服务(DoS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Synology | Synology Chat Server | * ~ 2.4.5-22148 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9548 | 6.5 MEDIUM | Synology Chat Server 2.4.5前XSS及文件读写漏洞 |
| CVE-2026-9491 | 4.3 MEDIUM | Synology Chat Server 2.4.5前Webhook存在SSRF漏洞 |
No comments yet