CVE-2024-47264: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47264?
CVE-2024-47264 has a high severity due to its potential for remote authenticated users with administrator privileges to delete arbitrary files.
How do I fix CVE-2024-47264?
To fix CVE-2024-47264, upgrade Synology Active Backup for Business to version 2.7.1-13234 or higher.
Who is affected by CVE-2024-47264?
CVE-2024-47264 affects users of Synology Active Backup for Business versions prior to 2.7.1-13234.
What type of vulnerability is CVE-2024-47264?
CVE-2024-47264 is classified as a path traversal vulnerability.
Can CVE-2024-47264 be exploited remotely?
Yes, CVE-2024-47264 can be exploited remotely by authenticated users with administrator privileges.