Synology-SA-18:16 Calendar
Publish Time: 2018-03-29 12:52:19 UTC+8
Last Updated: 2018-06-14 19:36:31 UTC+8
- Severity
- Moderate
- Status
- Resolved
Abstract
A vulnerability allows remote authenticated users to create arbitrary events via a susceptible version of Calendar.
Affected Products
Product | Severity | Fixed Release Availability |
---|---|---|
Calendar | Moderate | Upgrade to 2.1.2-0511 or above. |
Mitigation
None
Detail
- CVE-2018-8927
- Severity: Moderate
- CVSS3 Base Score: 5.4
- CVSS3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter.
Acknowledgement
Taien Wang (https://www.linkedin.com/in/taienwang/)
Revision
Revision | Date | Description |
---|---|---|
1 | 2018-03-29 | Initial public release. |
2 | 2018-06-14 | Disclosed vulnerability details. |