PT-2026-95315 · Synology · Diskstation Manager
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Synology DiskStation Manager (DSM) versions prior to 7.2.1-69057-12
Synology DiskStation Manager (DSM) versions prior to 7.2.2-72806-9
Synology DiskStation Manager (DSM) versions prior to 7.3.2-86009-4
Synology DiskStation Manager (DSM) versions prior to 7.4-90075
Description
An SQL Injection issue exists in the EventScheduler API. This occurs due to improper neutralization of special elements used in an SQL command, allowing remote authenticated users with administrator privileges to obtain non-sensitive information.
Recommendations
Update to version 7.2.1-69057-12 or later.
Update to version 7.2.2-72806-9 or later.
Update to version 7.3.2-86009-4 or later.
Update to version 7.4-90075 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Diskstation Manager