CVE-2019-11828: XSS
Published Jun 30, 2019
·Updated
Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Synology Office<3.1.4-2771
Event History
Jun 30, 2019
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11828?
CVE-2019-11828 has been designated as a moderate severity vulnerability.
2
How do I fix CVE-2019-11828?
To fix CVE-2019-11828, upgrade Synology Office to version 3.1.4-2771 or later.
3
Who is affected by CVE-2019-11828?
CVE-2019-11828 affects remote authenticated users of Synology Office versions prior to 3.1.4-2771.
4
What type of vulnerability is CVE-2019-11828?
CVE-2019-11828 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2019-11828?
Attackers can inject arbitrary web scripts or HTML into Synology Office through CVE-2019-11828.