Description
|
|
Multiple vulnerabilities have been reported in Synology DiskStation Manager, which can be exploited by malicious people to conduct cross-site scripting attacks and potentially compromise a vulnerable system.
1) The device bundles a vulnerable version of PHP.
For more information:
SA64529
2) Input passed via the "compound" GET parameter to webapi/entry.cgi is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
The vulnerabilities are reported in versions prior to 5.2-5565 Update 1.
|