CVE-2024-13987: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or write limited files in SRM and conduct limited denial-of-service via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13987?
CVE-2024-13987 has been classified as a high severity vulnerability due to its potential impact on system security.
How do I fix CVE-2024-13987?
To mitigate CVE-2024-13987, upgrade Synology RADIUS Server to version 3.0.27-0140 or later, as it addresses this vulnerability.
Who is affected by CVE-2024-13987?
CVE-2024-13987 affects users of Synology RADIUS Server versions prior to 3.0.27-0139, specifically users with administrator privileges.
What kind of attack can be executed through CVE-2024-13987?
CVE-2024-13987 can allow remote authenticated users to read or write limited files, and potentially conduct a limited denial-of-service attack.
What is the nature of the vulnerability in CVE-2024-13987?
CVE-2024-13987 is a Cross-site Scripting (XSS) vulnerability which results from improper handling of user input during web page generation.