CyberRota Analysis
AI-GeneratedA critical Cross-site Scripting vulnerability in Synology Chat Server versions prior to 2.4.5-22148 allows remote authenticated users to manipulate web page input, potentially leading to unauthorized file access and denial-of-service attacks within the DiskStation Manager (DSM). Organizations using affected versions should prioritize patching to mitigate risks associated with unauthorized data exposure and service disruptions.
Original NVD Description
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.