Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-67855
HistoryJul 15, 2022 - 12:00 a.m.

Synology Calendar Cross-Site Scripting Vulnerability (CNVD-2022-67855)

2022-07-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
8

0.001 Low

EPSS

Percentile

22.1%

Synology Calendar, a file protection program running on Synology NAS (Network Storage Server) devices from Synology Inc. of Taiwan, China, is vulnerable to a cross-site scripting vulnerability in versions prior to Synology Calendar 2.4.5-10930. The vulnerability stems from the program’s lack of data validation filtering of user-supplied data and output. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

0.001 Low

EPSS

Percentile

22.1%

Related for CNVD-2022-67855