Synology-SA-17:69 File Station
Publish Time: 2017-11-15 13:26:44 UTC+8
Last Updated: 2017-12-08 16:11:42 UTC+8
- Severity
- Important
- Status
- Resolved
Abstract
CVE-2017-15893 allows remote authenticated users to write arbitrary files via a vulnerable version of File Station.
Severity
- Impact: Important
- CVSS3 Base Score: 7.1
- CVSS3 Base Metrics: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected
- Products
- File Station before 1.1.1-0099
Description
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
Mitigation
None
Update Availability
To fix the security issue, please go to DSM > Package Center and update File Station to 1.1.1-0099 or above.