CVE-2024-53283: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53283?
CVE-2024-53283 has been categorized as a high-severity Cross-site Scripting vulnerability.
How do I fix CVE-2024-53283?
To mitigate CVE-2024-53283, update your Synology Router Manager to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53283?
CVE-2024-53283 affects remote authenticated users with administrator privileges on Synology Router Manager versions prior to 1.3.1-9346-10.
What is the impact of CVE-2024-53283?
The impact of CVE-2024-53283 allows attackers to inject arbitrary web scripts or HTML, potentially leading to unauthorized actions or data exposure.
Is there a way to detect CVE-2024-53283 on my network?
To detect CVE-2024-53283, monitor your Synology Router Manager logs for suspicious activities related to web script injections.