CVE-2020-27660: SQL Injection
Published Nov 30, 2020
·Updated
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
Affected Software
1 affected component
Synology SafeAccess<1.2.3-0234
Event History
Nov 30, 2020
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability?
The vulnerability ID for this SQL injection vulnerability is CVE-2020-27660.
2
What is the affected software?
The affected software is Synology SafeAccess version up to and exclusive of 1.2.3-0234.
3
What is the severity of CVE-2020-27660?
The severity of CVE-2020-27660 is critical with a CVSS score of 9.8.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by executing arbitrary SQL commands through the domain parameter in request.cgi.
5
Are there any available fixes for this vulnerability?
Yes, Synology has released a patch for this vulnerability. Please update to version 1.2.3-0234 or later to fix the vulnerability.