Beveiligingsadvies

CVE-2019-11829

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-06-30 15:05:12
Laatst bijgewerkt 2024-09-16 18:04:00
Toegewezen door synology
CVSS-score 7.3
Status PUBLISHED

Beschrijving

OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.