Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Oliver Kramer

#20013of 53,638
13Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-18719
6.5
2018-06-01
Synology · Synology Drive · CVE-2018-8921
**Name of the Vulnerable Software and Affected Versions** Synology Drive versions prior to 1.0.2-10275 **Description** The issue allows remote authenticated users to inject arbitrary web script or HTML via a malicious file name, exploiting a cross-site scripting (XSS) vulnerability in the File Sharing Notify Toast feature. **Recommendations** For versions prior to 1.0.2-10275, update to version 1.0.2-10275 or later to resolve the issue.
PT-2018-18720
6.5
2018-06-01
Synology · Synology Drive · CVE-2018-8922
**Name of the Vulnerable Software and Affected Versions** Synology Drive versions prior to 1.0.2-10275 **Description** The issue is related to improper access control, allowing remote authenticated users to access non-shared files or folders. The exact vectors used for this unauthorized access are not specified. **Recommendations** For versions prior to 1.0.2-10275, update to version 1.0.2-10275 or later to resolve the issue.