CVE-2018-12295: Seagate NAS OS

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.

Affected products

  • Seagate NAS OS: version 4.3.15.1 only

Published 2019-05-13. Last modified 2026-06-17.