Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unspecified vectors.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Synology Drive Server SQL注入漏洞
Vulnerability Description
Synology Drive Server是中国群晖(Synology)公司的一套协同办公套件。该产品包括文档管理、协同办公和文件同步备份等功能。 Synology Drive Server 3.0.4-12699之前版本、3.2.1-23280之前版本、3.5.0-26085之前版本和3.5.1-26102之前版本存在SQL注入漏洞,该漏洞源于系统同步守护进程SQL命令中特殊元素中和不当,可能导致远程攻击者注入SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A