First published: Tue Jul 12 2022(Updated: )
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Calendar | <2.4.5-10930 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22682 is an 'Improper neutralization of input during web page generation (Cross-site Scripting)' vulnerability in Event Management in Synology Calendar before version 2.4.5-10930, allowing remote authenticated users to inject arbitrary web script or HTML.
The severity of CVE-2022-22682 is medium with a CVSS score of 5.4.
CVE-2022-22682 allows remote authenticated users to inject arbitrary web script or HTML in Event Management of Synology Calendar.
To fix CVE-2022-22682, update Synology Calendar to version 2.4.5-10930 or later.
You can find more information about CVE-2022-22682 in the Synology security advisory at https://www.synology.com/security/advisory/Synology_SA_22_07.