CVE-2024-29238: SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29238?
CVE-2024-29238 is considered a critical vulnerability due to the potential for SQL Injection attacks that could compromise database integrity.
What kind of attacks can be executed via CVE-2024-29238?
CVE-2024-29238 allows remote authenticated users to inject arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
How can I fix CVE-2024-29238?
To fix CVE-2024-29238, update your Synology Surveillance Station to version 9.2.0-9289 or later.
Which versions of Synology Surveillance Station are affected by CVE-2024-29238?
CVE-2024-29238 affects Synology Surveillance Station versions prior to 9.2.0-9289 and 9.2.0-11289.
Is the Synology DiskStation Manager affected by CVE-2024-29238?
No, Synology DiskStation Manager versions 6.2, 7.1, and 7.2 do not have the vulnerability associated with CVE-2024-29238.