CVE-2024-53281: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53281?
CVE-2024-53281 has a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-53281?
To fix CVE-2024-53281, update your Synology Router Manager (SRM) to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53281?
CVE-2024-53281 affects remote authenticated users of Synology Router Manager versions prior to 1.3.1-9346-10.
What type of vulnerability is CVE-2024-53281?
CVE-2024-53281 is a cross-site scripting (XSS) vulnerability related to improper input neutralization in web page generation.
Can CVE-2024-53281 be exploited without authentication?
No, CVE-2024-53281 requires authentication to exploit the vulnerability.