First published: Mon Feb 07 2022(Updated: )
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | >=6.2<6.2.4-25556-3 | |
Synology DiskStation Manager | >=7.0<7.0.1-42218-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43929.
The severity of CVE-2021-43929 is medium.
The affected software is Synology DiskStation Manager (DSM) version 6.2 to 6.2.4-25556-3 and version 7.0 to 7.0.1-42218-2.
CVE-2021-43929 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the work flow management component of Synology DiskStation Manager (DSM).
Yes, the fix for CVE-2021-43929 is to upgrade Synology DiskStation Manager (DSM) to version 7.0.1-42218-2 or later.