CVE-2024-53279: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53279?
CVE-2024-53279 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-53279?
To fix CVE-2024-53279, update your Synology Router Manager to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53279?
CVE-2024-53279 affects Synology Router Manager versions prior to 1.3.1-9346-10, specifically targeting remote authenticated users with administrator privileges.
What types of attacks can exploit CVE-2024-53279?
CVE-2024-53279 can be exploited to perform cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
When was CVE-2024-53279 disclosed?
CVE-2024-53279 was disclosed in December 2024.