CVE-2018-13297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
01/04/2019
Last modified:
17/10/2024

Description

Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:synology:drive_server:*:*:*:*:*:*:*:* 1.1.2-10562 (excluding)


References to Advisories, Solutions, and Tools