Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.
2022-08-03T03:15:08.160
2025-01-14T19:29:55.853
Modified
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | synology | storage_analyzer | < 2.1.0-0390 | Yes |
Operating System | synology | diskstation_manager | 7.0 | No |
Operating System | synology | diskstation_manager | 7.1 | No |
Application | synology | storage_analyzer | < 2.0.1-0214 | Yes |
Operating System | synology | diskstation_manager | 6.2 | No |