CVE-2024-29232
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 28, 2024
Updated: Jan 14, 2025
CWE ID 89
Summary
CVE-2024-29232 is a vulnerability affecting the Alert.Enum webapi component in Synology Surveillance Station versions prior to 9.2.0-11289 and 9.2.0-9289. This issue involves the improper neutralization of special elements in SQL commands, leading to an SQL Injection vulnerability. Remote authenticated users can exploit this weakness by injecting their own SQL commands, potentially gaining unauthorized access to sensitive data or executing malicious actions within the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Synology DiskStation
- Synology Surveillance Station
Affected Vendors
- Synology