CVE-2019-11825: XSS
Published Jun 30, 2019
·Updated
Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
Affected Software
1 affected component
Synology Calendar<2.3.0-0615
Event History
Jun 30, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-11825?
CVE-2019-11825 is a cross-site scripting (XSS) vulnerability in the Event Editor component of Synology Calendar before version 2.3.0-0615.
2
How does CVE-2019-11825 affect Synology Calendar?
CVE-2019-11825 allows remote attackers to inject arbitrary web scripts or HTML into the title parameter of Synology Calendar.
3
What is the severity of CVE-2019-11825?
CVE-2019-11825 has a severity score of 5.4, which is considered medium.
4
How can I fix CVE-2019-11825 in Synology Calendar?
To fix CVE-2019-11825, update Synology Calendar to version 2.3.0-0615 or later.
5
Where can I find more information about CVE-2019-11825?
You can find more information about CVE-2019-11825 in the Synology security advisory Synology_SA_19_04.