CVE-2022-27613
Description
CVE-2022-27613 is an SQL injection in Synology CardDAV Server's webapi component that allows authenticated remote attackers to execute arbitrary SQL commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2022-27613 is an SQL injection in Synology CardDAV Server's webapi component that allows authenticated remote attackers to execute arbitrary SQL commands.
Vulnerability
An SQL injection vulnerability exists in the webapi component of Synology CardDAV Server versions before 6.0.10-0153. The vulnerability stems from improper neutralization of special elements used in an SQL command. This affects CardDAV Server for DSM 6.2. The vendor advisory rates this as Important with a CVSSv3.1 base score of 8.3 [1].
Exploitation
An attacker must have network access and valid low-privilege credentials to authenticate to the CardDAV Server. The specific attack vector is via the webapi component, though the exact inputs or parameters are not disclosed in the available references. No user interaction beyond authentication is required, and the attack complexity is low [1].
Impact
Successful exploitation allows a remote authenticated attacker to execute arbitrary SQL commands. This could lead to reading or modifying sensitive data (confidentiality and integrity impact: High) and potentially cause limited availability impact (Low) [1]. The attacker gains the ability to manipulate the underlying database, potentially affecting the CardDAV service and stored contact data.
Mitigation
Synology released the fix in CardDAV Server version 6.0.10-0153. Users should upgrade to this version or later. No workarounds are provided in the advisory [1]. The vulnerability was disclosed on 2022-07-28, with an initial advisory revision dated 2021-02-23 [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<6.0.10-0153+ 1 more
- (no CPE)range: <6.0.10-0153
- (no CPE)range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- www.synology.com/security/advisory/Synology_SA_21_06mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.