Impact
The EventScheduler API in Synology DiskStation Manager is vulnerable to SQL injection because user input is not properly escaped. An authenticated user with administrator privileges can send a crafted request to the API and cause arbitrary SQL statements to be executed, resulting in the exposure of non‑sensitive database information. This weakness is identified as CWE‑89.
Affected Systems
Synology DiskStation Manager versions prior to 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4 and 7.4‑90075 are affected. Administrators of these DSM installations are at risk if the EventScheduler API remains enabled.
Risk and Exploitability
The CVSS score of 2.7 categorizes the vulnerability as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires remote access to the DSM with administrator credentials, the risk is limited to environments where an attacker can obtain or guess such credentials. The impact of a successful exploitation is the disclosure of non‑sensitive data available to the authenticated administrator.
OpenCVE Enrichment