28Mar
CVE-2024-29238 | Synology Surveillance Station prior 9.2.0-9289/9.2.0-11289 WebAPI Log.CountByCategory sql injection (SA_24_04)
A vulnerability classified as critical was found in Synology Surveillance Station. Affected by this vulnerability is the functionLog.CountByCategory
of the component WebAPI. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-29238. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.