CVE-2017-11150

Publication date

2017-08-14 19:00:00

Family

synology

State

PUBLISHED

Description

Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents.