Impact
The vulnerability is an improper neutralization of input during web page generation (cross‑site scripting) in the extract domain of Synology Chat Server. An attacker who has valid authentication credentials can inject malicious JavaScript via a UI interaction, which is then executed in the context of the application. The injected code can read and write restricted files on the Synology device and trigger limited denial‑of‑service conditions. Although it does not provide arbitrary code execution, it enables a logged‑in user to tamper with critical files and disrupt availability for that user.
Affected Systems
Synology Chat Server versions prior to 2.4.5‑22148 are vulnerable. The affected product is Synology’s Chat Server component, which runs on Synology DSM devices.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session and interaction with the web UI that triggers the extract domain. The attacker’s ability to read or modify restricted files could facilitate further compromise if additional privileges are later obtained, but such upward privilege escalation is not directly supported by the present description.
OpenCVE Enrichment