CVE-2018-13299: Synology Calendar

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.

Affected products

  • Synology Calendar: before 2.2.2-0532 (fixed in 2.2.2-0532)

Published 2019-04-01. Last modified 2026-06-17.