Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29234


Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors.


Published

2024-03-28T07:16:06.830

Last Modified

2025-01-14T20:24:22.027

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application synology surveillance_station < 9.2.0-9289 Yes
Operating System synology diskstation_manager 6.2 No
Application synology surveillance_station < 9.2.0-11289 Yes
Operating System synology diskstation_manager 7.1 No
Operating System synology diskstation_manager 7.2 No

References