CVE-2018-8914

Publication date

2018-05-10 13:00:00

Family

synology

State

PUBLISHED

Description

SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.