Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology USB Copy before 2.2.0-1086 allows remote authenticated users to read or write arbitrary files via unspecified vectors.
2022-08-03T06:15:07.450
2025-01-14T19:29:55.853
Modified
CVSSv3.1: 5.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | usb_copy | < 2.2.0-1086 | Yes |
| Operating System | synology | diskstation_manager | 6.2 | No |
| Operating System | synology | diskstation_manager | 7.0 | No |
| Operating System | synology | diskstation_manager | 7.1 | No |