Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
affected
1.3 (semver) before 1.3.1-9346-13
affected
Any version before 1.3
unknown
Description
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
1.3 (semver) before 1.3.1-9346-13
Any version before 1.3
Credits
Qian Chen (@cq674350529) from Codesafe Team of Legendsec at QI-ANXIN Group
References
www.synology.com/...obal/security/advisory/Synology_SA_25_04 (Synology-SA-25:04 SRM)