CVE-2024-53280: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53280?
CVE-2024-53280 is classified as a high-severity vulnerability due to its potential impact on web security and user data integrity.
How do I fix CVE-2024-53280?
To remediate CVE-2024-53280, update your Synology Router Manager to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53280?
CVE-2024-53280 affects remote authenticated users with administrator privileges on vulnerable versions of Synology Router Manager.
What type of vulnerability is CVE-2024-53280?
CVE-2024-53280 is a Cross-site Scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
What are the potential consequences of CVE-2024-53280?
Exploitation of CVE-2024-53280 may lead to unauthorized access, data manipulation, or exposure of sensitive information.