CVE-2022-22686

Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:synology:calendar:*:*:*:*:*:*:*:*

History

01 Aug 2022, 12:44

Type Values Removed Values Added
First Time Synology
Synology calendar
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
References (CONFIRM) https://www.synology.com/security/advisory/Synology_SA_20_07 - (CONFIRM) https://www.synology.com/security/advisory/Synology_SA_20_07 - Vendor Advisory
CPE cpe:2.3:a:synology:calendar:*:*:*:*:*:*:*:*

26 Jul 2022, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-26 02:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-22686

Mitre link : CVE-2022-22686

CVE.ORG link : CVE-2022-22686


JSON object : View

Products Affected

synology

  • calendar
CWE
CWE-352

Cross-Site Request Forgery (CSRF)