312
VMScore

CVE-2020-27659

Published: 30/11/2020 Updated: 12/04/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess prior to 1.2.3-0234 allow remote malicious users to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synology safeaccess

Github Repositories

Synology-SA-20:25: SafeAccess - Multiple Vulnerabilities Safe Access Version: 121-0220 SRM Version : 123-8017 Update 4 Bug Hunter: Thomas FADY CVE: CVE-2020-27659 CVE-2020-27660 Advisory: Synology-SA-20:25 Timeline 01/05/2020: Vendor Disclosure 24/11/2020: Initial public release 30/11/2020: Disclosed vulnerability details Summary The first vulnerability described in