Junglewise Threat Intelligence

CVE-2025-13167: Synology Contacts cross-site scripting in contact functionality

CVE-2025-13167 · Severity: medium · CVSS 5.4 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology Contacts is an application used to manage address books and contact information on Synology NAS devices. A security flaw in the contact management feature allows an authenticated user to perform a cross-site scripting (XSS) attack. If successful, an attacker could read or modify certain non-sensitive files, potentially compromising the integrity of contact data or leading to unauthorized actions within the user's session.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the contact functionality of Synology Contacts before version 1.0.10-20659. The flaw stems from improper neutralization of input during web page generation (CWE-79). A remote authenticated attacker with low privileges can exploit this by injecting malicious scripts into contact fields. When another user views the affected contact, the script executes in their browser context, allowing the attacker to read or write specific files containing non-sensitive information. The vulnerability requires user interaction and has been addressed in version 1.0.10-20659.

Affected products

  • Synology Contacts for DSM 7.3 before 1.0.10-20659
  • Synology Contacts for DSM 7.2.2 before 1.0.10-20659
  • Synology Contacts for DSM 7.2.1 before 1.0.10-20659

Timeline

  • 2025-11-14: advisory: Initial public release of the advisory
  • 2026-05-27: disclosed: Vulnerability details disclosed and CVE published

References