在 Synology Chat Server 2.4.5-22148 之前的版本中,存在一个在网页生成过程中输入处理不当(“跨站脚本”)的漏洞。通过用户界面交互,远程经身份验证的用户可以利用该漏洞读取或写入受限文件,并在 DSM 中发起有限的拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Synology | Synology Chat Server | * ~ 2.4.5-22148 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40541 | 9.0 CRITICAL | Synology Chat Server 2.4.5 前跨站脚本漏洞 |
| CVE-2026-9491 | 4.3 MEDIUM | Synology Chat Server 2.4.5前Webhook存在SSRF漏洞 |
No comments yet