CVE-2022-22682: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22682?
CVE-2022-22682 is an 'Improper neutralization of input during web page generation (Cross-site Scripting)' vulnerability in Event Management in Synology Calendar before version 2.4.5-10930, allowing remote authenticated users to inject arbitrary web script or HTML.
What is the severity of CVE-2022-22682?
The severity of CVE-2022-22682 is medium with a CVSS score of 5.4.
How does CVE-2022-22682 impact Synology Calendar?
CVE-2022-22682 allows remote authenticated users to inject arbitrary web script or HTML in Event Management of Synology Calendar.
How can I fix CVE-2022-22682?
To fix CVE-2022-22682, update Synology Calendar to version 2.4.5-10930 or later.
Where can I find more information about CVE-2022-22682?
You can find more information about CVE-2022-22682 in the Synology security advisory at https://www.synology.com/security/advisory/Synology_SA_22_07.