Impact
An improper neutralization of input during web page generation, specifically in the extract domain functionality, is present in Synology Chat Server versions before 2.4.5-22148. The vulnerability allows a remote authenticated user to interact with the UI to read or write arbitrary files and to conduct denial‑of-service attacks against the DiskStation Manager (DSM). This can result in unauthorized file manipulation or service disruption.
Affected Systems
The affected product is Synology Chat Server. Versions earlier than 2.4.5-22148 are vulnerable. The issue exists within the DSM web interface used to manage the chat service.
Risk and Exploitability
The CVSS score of 9.0 classifies this as a critical vulnerability, and while the EPSS score is not available, the lack of a KEV listing does not diminish the seriousness of the flaw. The likely attack vector is an authenticated attacker who can access the chat server’s UI on the DSM host. Such an attacker can upload or overwrite files, potentially modifying or deleting critical data, or crash the application through crafted input. The high severity and potential for arbitrary file access and denial‑of-service make immediate remediation essential.
OpenCVE Enrichment