← Back to browse · API

CVE-2020-27660

Severity
CRITICAL
CVSS
9.6
EPSS
0.04555
Risk score
39.99
CISA KEV
No
PoC
No
Published
2020-11-30
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2020-20167, GHSA-CP77-JFVP-QPXX
Products
Synology:Safe Access unspecified <1.2.3-0234
Sources
euvd EUVD-2020-20167

Description

SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.

References