Injection Vulnerability in Synology DiskStation Manager by Synology
CVE-2021-43929
5.4MEDIUM
What is CVE-2021-43929?
An improper neutralization of special elements in output vulnerability exists in Synology DiskStation Manager, allowing remote authenticated users to inject arbitrary web scripts or HTML. This issue may lead to unauthorized access or manipulation of web-based applications, highlighting the critical importance of ensuring proper input validation and sanitization mechanisms.
Affected Version(s)
DiskStation Manager (DSM) < 7.0.1-42218-2