Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
History

Fri, 01 Aug 2025 04:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors. Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors.
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Synology surveillance Station
CPEs cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
Vendors & Products Synology
Synology diskstation Manager
Synology surveillance Station

cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published: 2024-03-28T06:08:34.641Z

Updated: 2025-08-01T03:46:55.183Z

Reserved: 2024-03-19T06:14:19.314Z

Link: CVE-2024-29227

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:55.403Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-28T07:15:59.770

Modified: 2025-08-04T19:09:20.870

Link: CVE-2024-29227

cve-icon Redhat

No data.