CVE-2024-29234: SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29234?
CVE-2024-29234 is classified as a high severity vulnerability due to its potential for SQL injection, allowing remote authenticated users to manipulate SQL commands.
How do I fix CVE-2024-29234?
To fix CVE-2024-29234, upgrade Synology Surveillance Station to version 9.2.0-11289 or later as specified in the advisory.
What types of systems are affected by CVE-2024-29234?
CVE-2024-29234 affects Synology Surveillance Station versions prior to 9.2.0-11289.
Who is at risk for CVE-2024-29234?
Remote authenticated users of vulnerable versions of Synology Surveillance Station are at risk for CVE-2024-29234.
What role does SQL injection play in CVE-2024-29234?
SQL injection allows attackers to execute malicious SQL queries in the database, potentially leading to unauthorized data access or manipulation.