Relative Path Traversal Vulnerability in Synology Calendar Product
CVE-2018-13299
4.3MEDIUM
Summary
A relative path traversal vulnerability exists in the Attachment Uploader component of Synology Calendar, allowing remote authenticated users to exploit the filename parameter to upload arbitrary files. This issue affects versions of the software before 2.2.2-0532, and it's crucial for users to apply the latest updates to mitigate potential security risks. For further details, please refer to the official security advisory provided by Synology.
Affected Version(s)
Calendar < 2.2.2-0532
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved