Relative Path Traversal Vulnerability in Synology Calendar Product
CVE-2018-13299
4.3MEDIUM
What is CVE-2018-13299?
A relative path traversal vulnerability exists in the Attachment Uploader component of Synology Calendar, allowing remote authenticated users to exploit the filename parameter to upload arbitrary files. This issue affects versions of the software before 2.2.2-0532, and it's crucial for users to apply the latest updates to mitigate potential security risks. For further details, please refer to the official security advisory provided by Synology.
Affected Version(s)
Calendar < 2.2.2-0532