VYPR

webapi

by Synology

CVEs (1)

  • CVE-2022-27621MedAug 3, 2022
    risk 0.36cvss 5.5epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology USB Copy before 2.2.0-1086 allows remote authenticated users to read or write arbitrary files via unspecified vectors.