Description
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.
References
https://www.synology.com/security/advisory/Synology_SA_21_06
Vendor Advisory
https://www.synology.com/security/advisory/Synology_SA_21_06
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
8.3 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-07-28T05:15:07.957Z
3 years agoLast modified
2024-11-21T05:56:01.577Z
1 year ago