Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Synology Hyper Backup 路径遍历漏洞
Vulnerability Description
Synology Hyper Backup是中国群晖(Synology)公司的一个提供多版本数据备份、复制与灾难恢复能力的备份管理系统。 Synology Hyper Backup 4.1.2-4036之前版本存在路径遍历漏洞,该漏洞源于Backup.Repository webapi组件路径限制不当,可能导致远程认证管理员通过未指定向量写入特定文件。
CVSS Information
N/A
Vulnerability Type
N/A