CVE-2018-8928: XSS
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) familyname, (2) givenname, or (3) additionalname parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8928?
CVE-2018-8928 is a cross-site scripting (XSS) vulnerability in the Address Book Editor in Synology CardDAV Server before version 6.0.8-0086.
How does CVE-2018-8928 impact users?
CVE-2018-8928 allows remote authenticated users to inject arbitrary web script or HTML via certain parameters, potentially leading to unauthorized access or data manipulation.
What software is affected by CVE-2018-8928?
The Synology CardDAV Server versions up to and excluding 6.0.8-0086 are affected by CVE-2018-8928.
How severe is CVE-2018-8928?
CVE-2018-8928 has a severity rating of medium (5.4) on the Common Vulnerability Scoring System (CVSS) scale.
How can I fix CVE-2018-8928?
To fix CVE-2018-8928, users should update their Synology CardDAV Server to version 6.0.8-0086 or later, as advised by Synology in their security advisory.