First published: Mon Apr 01 2019(Updated: )
Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.
Credit: security@synology.com security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Drive Server | <1.1.2-10562 | |
Synology Drive Server | <1.1.2-10562 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13297 is classified as a medium severity vulnerability.
To fix CVE-2018-13297, update Synology Drive to version 1.1.2-10562 or later.
CVE-2018-13297 can allow remote attackers to access sensitive system information if exploited.
CVE-2018-13297 affects Synology Drive versions prior to 1.1.2-10562.
Yes, CVE-2018-13297 can be exploited remotely through manipulation of the dsm_path parameter.