CVE-2021-43929: XSS
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2021-43929.
What is the severity of CVE-2021-43929?
The severity of CVE-2021-43929 is medium.
What is the affected software?
The affected software is Synology DiskStation Manager (DSM) version 6.2 to 6.2.4-25556-3 and version 7.0 to 7.0.1-42218-2.
How does CVE-2021-43929 work?
CVE-2021-43929 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the work flow management component of Synology DiskStation Manager (DSM).
Is there a fix for CVE-2021-43929?
Yes, the fix for CVE-2021-43929 is to upgrade Synology DiskStation Manager (DSM) to version 7.0.1-42218-2 or later.