Security Advisory

CVE-2018-13299

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-04-01 14:31:19
Last updated 2024-09-16 19:24:24
Assigner synology
State PUBLISHED

Description

Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.