Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
History

Fri, 01 Aug 2025 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Aug 2025 05:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.

Tue, 14 Jan 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Synology surveillance Station
CPEs cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
Vendors & Products Synology
Synology diskstation Manager
Synology surveillance Station

cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published: 2024-03-28T06:26:12.750Z

Updated: 2025-08-01T04:46:13.156Z

Reserved: 2024-03-19T06:14:19.314Z

Link: CVE-2024-29234

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:54.645Z

cve-icon NVD

Status : Modified

Published: 2024-03-28T07:16:06.830

Modified: 2025-08-01T05:15:35.470

Link: CVE-2024-29234

cve-icon Redhat

No data.