Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Synology Surveillance Station SQL注入漏洞
Vulnerability Description
Synology Surveillance Station是中国群晖科技(Synology)公司的一个应用程序。提供智能监控和视频管理工具来保护您的宝贵资产。 Synology Surveillance Station 9.2.0-11289 版本之前存在SQL注入漏洞,该漏洞源于 webapi 组件的 Alert.Enum 方法存在 SQL 注入问题。经过身份验证的远程攻击者通过该漏洞可以注入 SQL 命令。
CVSS Information
N/A
Vulnerability Type
N/A