Impact
A cross‑site scripting flaw is present in the Video API of Synology DiskStation Manager (DSM) before specific patched releases. The flaw arises from improper neutralization of user‑supplied input during web page generation, enabling an attacker to inject malicious script code. When exploited by a remote authenticated user, the script can read or write a restricted set of files on the NAS, giving the attacker partial data exfiltration or modification capability.
Affected Systems
Synology’s DiskStation Manager firmware versions prior to 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 are affected. These versions run on Synology NAS devices that provide the Video API web service. Users with local or network credentials that can start the video player are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating a moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the issue is not listed in the CISA KEV catalog. The attack requires the attacker to be an authenticated user with permissions to launch the video player, so it is not a public unauthenticated vector but still poses significant risk in environments where many users have such privileges.
OpenCVE Enrichment