First published: Mon Jul 25 2022(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Audio Station | <6.5.4-3367 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-27611.
The title of this vulnerability is 'Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in webapi component in Synology Audio Station before 6.5.4-3367'.
The severity of CVE-2022-27611 is high with a severity value of 8.1.
CVE-2022-27611 affects Synology Audio Station versions before 6.5.4-3367.
Remote authenticated users can exploit CVE-2022-27611 to delete arbitrary files via unspecified vectors.