CVE-2018-13290: Infoleak
Published Apr 1, 2019
·Updated
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the filepath parameter.
Affected Software
1 affected component
Synology Router Manager>=1.1<1.1.7-6941-2
Event History
Apr 1, 2019
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this information exposure vulnerability?
The vulnerability ID for this information exposure vulnerability is CVE-2018-13290.
2
What is the severity of CVE-2018-13290?
The severity of CVE-2018-13290 is medium.
3
How does this vulnerability affect Synology Router Manager (SRM)?
This vulnerability affects Synology Router Manager (SRM) before version 1.1.7-6941-2.
4
How can remote authenticated users exploit this vulnerability?
Remote authenticated users can exploit this vulnerability to determine the existence of files or obtain sensitive information of files by using the file_path parameter.
5
Is there any fix available for this vulnerability?
Yes, a fix for this vulnerability is available in version 1.1.7-6941-2 of Synology Router Manager (SRM).