Server-Side Request Forgery Vulnerability in Synology Chat
CVE-2017-15886
6.5MEDIUM
What is CVE-2017-15886?
A server-side request forgery (SSRF) vulnerability exists in Synology Chat prior to version 2.0.0-1124, enabling remote authenticated users to exploit the application by crafting malicious URIs. This security flaw may allow attackers to access and download arbitrary local files from the server, posing a significant risk to sensitive data and system integrity.
Affected Version(s)
Chat before 2.0.0-1124