First published: Mon Nov 30 2020(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology SafeAccess | <1.2.3-0234 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27659 is classified as a medium severity vulnerability due to its potential to exploit cross-site scripting vulnerabilities.
To fix CVE-2020-27659, upgrade Synology SafeAccess to version 1.2.3-0234 or later.
The potential impacts of CVE-2020-27659 include unauthorized access to user accounts and data through cross-site scripting attacks.
CVE-2020-27659 affects users of Synology SafeAccess versions prior to 1.2.3-0234.
Yes, CVE-2020-27659 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.