CVE-2018-13294: Infoleak
Published Apr 1, 2019
·Updated
Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter.
Affected Software
1 affected component
Synology Application Service<1.5.4-0320
Event History
Apr 1, 2019
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-13294?
CVE-2018-13294 has been assigned a Medium severity rating due to the potential for information exposure.
2
How do I fix CVE-2018-13294?
To fix CVE-2018-13294, update the Synology Application Service to version 1.5.4-0320 or later.
3
Who is affected by CVE-2018-13294?
CVE-2018-13294 affects remote authenticated users of Synology Application Service versions prior to 1.5.4-0320.
4
What type of vulnerability is CVE-2018-13294?
CVE-2018-13294 is categorized as an information exposure vulnerability.
5
What can be exposed due to CVE-2018-13294?
CVE-2018-13294 allows remote authenticated users to obtain sensitive system information via the uid parameter.