CVE-2018-8920Improper Encoding or Escaping of Output in Synology Diskstation Manager

Severity
7.2HIGHNVD
EPSS
0.4%
top 39.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateMay 13

Description

Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5synology/diskstation_managerunspecified6.1.6-15266
NVDsynology/diskstation_manager< 6.1.6-15266

🔴Vulnerability Details

2
GHSA
GHSA-6972-2gcx-5qwg: Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 62022-05-13
CVEList
CVE-2018-8920: Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 62018-12-24
CVE-2018-8920 — Improper Encoding or Escaping of Output | cvebase