CVE-2024-45538

Source
https://cve.org/CVERecord?id=CVE-2024-45538
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45538.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45538
Published
2025-12-04T15:15:54.290Z
Modified
2026-03-12T07:18:10.409276Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "7.2.1-69057"
            },
            {
                "fixed": "7.2.1-69057-2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.2-72803"
            },
            {
                "fixed": "7.2.2-72806"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "3.1-23028"
            },
            {
                "fixed": "3.1.4-23079"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45538.json"