Filtered by vendor Synology Subscriptions
Filtered by product Safeaccess Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-27660 1 Synology 1 Safeaccess 2024-09-17 9.6 Critical
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
CVE-2020-27659 1 Synology 1 Safeaccess 2024-09-17 8.4 High
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.