Path Traversal in Synology Active Backup for Business Affects User Data Access
CVE-2024-47266
2.7LOW
What is CVE-2024-47266?
A Path Traversal vulnerability in Synology's Active Backup for Business allows remote authenticated users with administrator privileges to access certain files that should be restricted. This flaw exists in the share file list functionality and may let users read non-sensitive information through unspecified methods, posing a risk to data integrity and confidentiality.
Affected Version(s)
Active Backup for Business *
Active Backup for Business * < 2.7.1-13234
Active Backup for Business * < 2.7.1-23234