First published: Mon Apr 01 2019(Updated: )
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | >=1.1<1.1.7-6941-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information exposure vulnerability is CVE-2018-13290.
The severity of CVE-2018-13290 is medium.
This vulnerability affects Synology Router Manager (SRM) before version 1.1.7-6941-2.
Remote authenticated users can exploit this vulnerability to determine the existence of files or obtain sensitive information of files by using the file_path parameter.
Yes, a fix for this vulnerability is available in version 1.1.7-6941-2 of Synology Router Manager (SRM).