• caglararli@hotmail.com
  • 05386281520

CVE-2024-29234 | Synology Surveillance Station prior 9.2.0-9289/9.2.0-11289 WebAPI Group.Save sql injection (SA_24_04)

Çağlar Arlı      -    65 Views

CVE-2024-29234 | Synology Surveillance Station prior 9.2.0-9289/9.2.0-11289 WebAPI Group.Save sql injection (SA_24_04)

A vulnerability, which was classified as critical, was found in Synology Surveillance Station. Affected is the function Group.Save of the component WebAPI. The manipulation leads to sql injection. This vulnerability is traded as CVE-2024-29234. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.