VYPR
Unrated severityNVD Advisory· Published Jul 5, 2018· Updated Sep 17, 2024

CVE-2018-8928

CVE-2018-8928

Description

Stored XSS in Synology CardDAV Server Address Book Editor allows authenticated users to inject arbitrary web script via contact name fields.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Synology CardDAV Server Address Book Editor allows authenticated users to inject arbitrary web script via contact name fields.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the Address Book Editor component of Synology CardDAV Server prior to version 6.0.8-0086 [1]. The flaw allows remote authenticated users to inject arbitrary web script or HTML via the family_name, given_name, or additional_name parameters when creating or editing a contact. The injected script is stored and executed when other users view the affected contact entry.

Exploitation

An attacker must have valid credentials for the CardDAV Server. They can craft a malicious payload (e.g., JavaScript) in any of the three vulnerable fields during contact creation or modification. When another authenticated user accesses the Address Book and views the crafted contact, the payload executes in the context of that user's browser session. No additional user interaction beyond viewing the contact is required.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to theft of session cookies, unauthorized actions on behalf of the victim, or defacement of the Address Book interface. The CVSS v3 base score is 6.5 (Medium) with a vector of AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L, indicating a scope change and limited impact on confidentiality, integrity, and availability [1].

Mitigation

Synology has released CardDAV Server version 6.0.8-0086 to address this vulnerability. Users should upgrade to this version or later immediately [1]. No workarounds are provided in the advisory. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Synology/CardDAV Serverllm-fuzzy2 versions
    <6.0.8-0086+ 1 more
    • (no CPE)range: <6.0.8-0086
    • (no CPE)range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.