Impact
Based on the description, an improper neutralization of input during web page generation (CWE‑79) in Synology DiskStation Manager's Theme API can allow a remote authenticated administrator to inject malicious script content into pages served by the DSM interface. If successfully exploited, the attacker could execute arbitrary JavaScript within the context of the login session, potentially leading to cookie theft, credential compromise, or the ability to read and write a limited set of files exposed through DSM. The impact relies on the privilege level of the authenticated user and can lead to confidentiality and integrity issues.
Affected Systems
Synology DiskStation Manager (DSM) versions before 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, and 7.4‑90075 are vulnerable. These include devices running DSM 7.x releases prior to the mentioned patch levels.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk, primarily due to the requirement of remote authentication with administrator privileges. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. However, because the flaw can be exploited via the Web UI, any exposed DSM instance with an administrative account remains a potential target. The attack vector is inferred to be remote, authenticated access to the Theme API through the DSM web interface, which would enable script injection.
OpenCVE Enrichment