Information Exposure in Synology File Station Affects Sensitive Data Access
CVE-2018-13288
5.3MEDIUM
Summary
An information exposure vulnerability exists in the SYNO.FolderSharing.List component of Synology File Station, allowing remote attackers to gain unauthorized access to sensitive information. This issue arises specifically through improper handling of the folder_path or real_path parameters. Users of affected versions should take immediate action to secure their installations and mitigate potential data breaches.
Affected Version(s)
File Station < 1.2.3-0252
File Station < 1.1.5-0125
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved