VendorsSynologyfile_stationany version
Vulnerabilities

Synology File Station any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-15893
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
Published 2017-12-08 · Modified
6.5EPSS 0.018
CVE-2018-8923
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
Published 2018-06-05 · Modified
6.5EPSS 0.008
CVE-2018-13288
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
Published 2019-04-01 · Modified
5.3EPSS 0.015