vulnti.work

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or…

Medium CVSS 5.9
CVECVE-2024-13987
First seen2026-09-26 22:16 UTC
Disclosed2025-08-29 08:15 UTC
Last updated2026-09-26 22:16 UTC
Channel statusauto

Summary

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or write limited files in SRM and conduct limited denial-of-service via unspecified vectors.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD