CVE-2018-8927: Medium severity Synology Calendar vulnerability
Published Jun 14, 2018
·Updated
Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) calid or (2) originalcalid parameter.
Affected Software
1 affected component
Synology Calendar<2.1.2-0511
Event History
Jun 14, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-8927?
CVE-2018-8927 is an improper authorization vulnerability in SYNO.Cal.Event in Calendar before version 2.1.2-0511.
2
How does CVE-2018-8927 impact users?
CVE-2018-8927 allows remote authenticated users to create arbitrary events in the affected Calendar software.
3
How severe is CVE-2018-8927?
CVE-2018-8927 has a severity rating of 6.5 (Medium).
4
What software versions are affected by CVE-2018-8927?
The Synology Calendar software versions up to and excluding 2.1.2-0511 are affected by CVE-2018-8927.
5
How can this vulnerability be fixed?
To fix CVE-2018-8927, users should update their Calendar software to version 2.1.2-0511 or higher.