CVE-2018-8914: SQL Injection
Published May 10, 2018
·Updated
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.
Affected Software
2 affected components
Synology Media Server>=1.4<1.4-2654
Synology Media Server>=1.7<1.7.6-2842
Event History
May 10, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8914?
The severity of CVE-2018-8914 is critical.
2
How does CVE-2018-8914 affect Synology Media Server?
CVE-2018-8914 affects Synology Media Server versions before 1.7.6-2842 and before 1.4-2654.
3
What is the CVE ID of the SQL injection vulnerability in UPnP DMA?
The CVE ID of the SQL injection vulnerability in UPnP DMA is CVE-2018-8914.
4
What can remote attackers do with CVE-2018-8914?
Remote attackers can execute arbitrary SQL commands via the ObjectID parameter.
5
How can I fix CVE-2018-8914 in Synology Media Server?
To fix CVE-2018-8914 in Synology Media Server, update to version 1.7.6-2842 or version 1.4-2654.