Filtered by vendor Synology Subscriptions
Filtered by product Sso Server Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-16775 1 Synology 1 Sso Server 2024-09-17 N/A
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
CVE-2022-27620 1 Synology 2 Diskstation Manager, Sso Server 2024-09-16 6.8 Medium
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.