CVE-2017-15891: Medium severity synology calendar vulnerability
Published Dec 8, 2017
·Updated
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
Affected Software
1 affected component
Synology Calendar<2.0.1-0242
Event History
Dec 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2017-15891.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242'.
3
What is the severity of CVE-2017-15891?
The severity of CVE-2017-15891 is medium with a CVSS score of 6.5.
4
How does CVE-2017-15891 affect Synology Calendar?
CVE-2017-15891 affects Synology Calendar before version 2.0.1-0242.
5
How can the vulnerability be exploited?
The vulnerability can be exploited by remote authenticated users to modify calendar events via unspecified vectors.