Synology · Synology Mail Station · CVE-2021-43928
**Name of the Vulnerable Software and Affected Versions**
Synology Mail Station versions prior to 20211105-10315
**Description**
The issue is related to the improper neutralization of special elements used in an OS command, allowing remote authenticated users to execute arbitrary commands. This is due to an 'OS Command Injection' vulnerability in the mail sending and receiving component.
**Recommendations**
For versions prior to 20211105-10315, update to version 20211105-10315 or later to resolve the issue.