Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-82572
HistoryJul 28, 2022 - 12:00 a.m.

Synology Calendar Cross-Site Request Forgery Vulnerability

2022-07-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.0005 Low

EPSS

Percentile

19.1%

Synology Calendar, a file protection application running on Synology NAS devices from Synology, Taiwan, China, is vulnerable to cross-site request spoofing in versions prior to Synology Calendar 2.3.4-0631, which stems from a webapi component that does not adequately validate that the request is from a trusted user. An attacker could use this vulnerability to spoof malicious requests to trick victims into clicking through to perform sensitive actions.

0.0005 Low

EPSS

Percentile

19.1%

Related for CNVD-2022-82572