在 Synology Chat Server 2.4.5-22148 之前的版本中,webhook 中存在一个服务器端请求伪造(SSRF)漏洞,该漏洞允许经过身份验证的远程用户获取非敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Synology | Synology Chat Server | * ~ 2.4.5-22148 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40541 | 9.0 CRITICAL | Synology Chat Server 2.4.5 前跨站脚本漏洞 |
| CVE-2026-9548 | 6.5 MEDIUM | Synology Chat Server 2.4.5前XSS及文件读写漏洞 |
No comments yet