Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
2024-03-28T07:16:03.380
2025-08-04T19:09:18.470
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | synology | surveillance_station | < 9.2.0-9289 | Yes |
Operating System | synology | diskstation_manager | 6.2 | No |
Application | synology | surveillance_station | < 9.2.0-11289 | Yes |
Operating System | synology | diskstation_manager | 7.1 | No |
Operating System | synology | diskstation_manager | 7.2 | No |