VYPR
Medium severity5.4NVD Advisory· Published May 27, 2026

CVE-2025-13167

CVE-2025-13167

Description

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in Synology Contacts allows authenticated users to read/write non-sensitive files; fixed in version 1.0.10-20659.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the contact functionality of Synology Contacts before version 1.0.10-20659 [1]. The application fails to properly neutralize user-supplied input when generating web pages, allowing injection of arbitrary HTML and JavaScript. The vulnerability requires an authenticated user to create or edit a contact with malicious content.

Exploitation

An attacker with remote authenticated access to Synology Contacts can craft a contact entry containing malicious script. When another authenticated user views or interacts with that contact (e.g., by opening the contact detail page), the injected script executes in the context of the victim's session [1]. The CVSS vector indicates user interaction is required (UI:R), meaning the victim must perform some action to trigger the exploit [1].

Impact

Successful exploitation allows the attacker to read or write specific files on the system that contain non-sensitive information. The scope of impact is changed (S:C), meaning the vulnerability can affect resources beyond the vulnerable component, but confidentiality and integrity impacts are limited to low severity [1]. No sensitive data such as credentials or system configuration files are disclosed.

Mitigation

Synology has released fixed versions for DSM 7.3, 7.2.2, and 7.2.1: upgrade to Synology Contacts 1.0.10-20659 or above [1]. No workarounds are available; updating the package is the only mitigation [1]. The vulnerability is not known to be listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.