Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29230


Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.


Published

2024-03-28T07:16:03.380

Last Modified

2025-08-04T19:09:18.470

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application synology surveillance_station < 9.2.0-9289 Yes
Operating System synology diskstation_manager 6.2 No
Application synology surveillance_station < 9.2.0-11289 Yes
Operating System synology diskstation_manager 7.1 No
Operating System synology diskstation_manager 7.2 No

References