CVE-2018-13281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
31/10/2018
Last modified:
14/01/2025

Description

Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*
cpe:2.3:a:synology:vs960hd:-:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.1 (including) 6.1.7-15284-2 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.2 (including) 6.2-23739-2 (excluding)
cpe:2.3:o:synology:diskstation_manager:5.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.0:*:*:*:*:*:*:*