High severity7.8NVD Advisory· Published Aug 14, 2017· Updated May 13, 2026
CVE-2017-11150
CVE-2017-11150
Description
Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.synology.com/en-global/support/security/Synology_SA_17_26_OfficenvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.