CVE-2018-13299: Path Traversal
Published Apr 1, 2019
·Updated
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
Affected Software
1 affected component
Synology Calendar<2.2.2-0532
Event History
Apr 1, 2019
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-13299?
CVE-2018-13299 is a relative path traversal vulnerability in Attachment Uploader in Synology Calendar before version 2.2.2-0532.
2
How does CVE-2018-13299 affect Synology Calendar?
CVE-2018-13299 allows remote authenticated users to upload arbitrary files via the filename parameter.
3
What is the severity of CVE-2018-13299?
CVE-2018-13299 has a severity score of 6.5 (medium).
4
How can I fix CVE-2018-13299?
To fix CVE-2018-13299, update Synology Calendar to version 2.2.2-0532 or later.
5
Where can I find more information about CVE-2018-13299?
You can find more information about CVE-2018-13299 on the Synology security advisory page: [Synology_SA_18_54](https://www.synology.com/security/advisory/Synology_SA_18_54).