CVE-2024-53287
23.07.2025, 05:15
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
Vendor | Product | Version |
---|---|---|
synology | router_manager | 1.3 ≤ 𝑥 < 1.3.1-9346 |
synology | router_manager | 1.3.1-9346 |
synology | router_manager | 1.3.1-9346:update1 |
synology | router_manager | 1.3.1-9346:update10 |
synology | router_manager | 1.3.1-9346:update2 |
synology | router_manager | 1.3.1-9346:update3 |
synology | router_manager | 1.3.1-9346:update4 |
synology | router_manager | 1.3.1-9346:update5 |
synology | router_manager | 1.3.1-9346:update6 |
synology | router_manager | 1.3.1-9346:update7 |
synology | router_manager | 1.3.1-9346:update8 |
synology | router_manager | 1.3.1-9346:update9 |
𝑥
= Vulnerable software versions