Description
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.
Published: 2026-05-27
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation creates a Cross‑Site Scripting (XSS) flaw in the contact functionality of Synology Contacts. The vulnerability can be exploited by users who are authenticated to the system, allowing them to read or write specific files that contain non‑sensitive data. The weakness stems from inadequate filtering of user input before rendering output, which can result in the execution of arbitrary scripts within the browser context of an authenticated session. This compromises the confidentiality and integrity of user‑controlled content and may aid in further lateral movement.

Affected Systems

The affected product is Synology Contacts, any deployment using Synology Contacts version prior to 1.0.10‑20659. No specific version numbers beyond the upper bound are listed, so all earlier releases are potential targets.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity. No EPSS value is provided, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated web session where the attacker submits specially crafted input through the contact interface, resulting in client‑side script execution that can read or modify accessible files. The need for authentication limits the attack horizon to users who already have legitimate credentials, but it still permits potentially destructive actions within the sandbox of the web application.

Generated by OpenCVE AI on May 27, 2026 at 10:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Synology Contacts to version 1.0.10‑20659 or later, which addresses the XSS flaw.
  • Restrict user permissions so that only trusted accounts can access the contact functionality or disable the feature entirely if it is not required.
  • Monitor application logs for anomalous input patterns or repeated attempts to inject script content into contact fields.

Generated by OpenCVE AI on May 27, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting in Synology Contacts Contact Functionality

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-05-27T08:34:19.095Z

Reserved: 2025-11-14T06:51:13.775Z

Link: CVE-2025-13167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-27T09:16:26.483

Modified: 2026-05-27T09:16:26.483

Link: CVE-2025-13167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T11:00:13Z

Weaknesses