CVE-2024-29236: SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29236?
CVE-2024-29236 has a high severity rating due to the potential for SQL injection attacks.
How can I fix CVE-2024-29236?
To remediate CVE-2024-29236, update Synology Surveillance Station to version 9.2.0-9289 or later.
What systems are affected by CVE-2024-29236?
CVE-2024-29236 affects Synology Surveillance Station versions earlier than 9.2.0-9289 and 9.2.0-11289.
Who can exploit CVE-2024-29236?
CVE-2024-29236 can be exploited by remote authenticated users with access to the AudioPattern.Delete webapi component.
What type of vulnerability is CVE-2024-29236?
CVE-2024-29236 is classified as an SQL injection vulnerability, allowing attackers to inject malicious SQL commands.