First published: Thu Feb 13 2025(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Active Backup for Business Agent | <2.7.1-13234 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47264 has a high severity due to its potential for remote authenticated users with administrator privileges to delete arbitrary files.
To fix CVE-2024-47264, upgrade Synology Active Backup for Business to version 2.7.1-13234 or higher.
CVE-2024-47264 affects users of Synology Active Backup for Business versions prior to 2.7.1-13234.
CVE-2024-47264 is classified as a path traversal vulnerability.
Yes, CVE-2024-47264 can be exploited remotely by authenticated users with administrator privileges.