CVE-2018-13288: Infoleak
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folderpath or (2) realpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13288?
CVE-2018-13288 is classified as a medium severity vulnerability due to the risk of information exposure.
How do I fix CVE-2018-13288?
To fix CVE-2018-13288, update Synology File Station to version 1.2.3-0252 or later, or 1.1.5-0126 or later.
What kind of information can be exposed due to CVE-2018-13288?
CVE-2018-13288 may allow attackers to obtain sensitive information through the folder_path or real_path parameters.
Which versions of Synology File Station are affected by CVE-2018-13288?
CVE-2018-13288 affects Synology File Station versions before 1.2.3-0252 and versions before 1.1.5-0125.
Is CVE-2018-13288 a remote vulnerability?
Yes, CVE-2018-13288 is a remote vulnerability that allows attackers to exploit it without physical access to the system.