First published: Fri Jun 18 2021(Updated: )
Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Calendar | <2.4.0-0761 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34812 is a vulnerability in the php component in Synology Calendar before version 2.4.0-0761 that allows remote attackers to obtain sensitive information through the use of hard-coded credentials.
CVE-2021-34812 affects Synology Calendar before version 2.4.0-0761, potentially allowing remote attackers to obtain sensitive information.
The severity of CVE-2021-34812 is high and has a severity value of 7.5.
To fix CVE-2021-34812, users should update Synology Calendar to version 2.4.0-0761 or later.
More information about CVE-2021-34812 can be found in the Synology security advisory: https://www.synology.com/security/advisory/Synology_SA_21_12.