CVE-2018-13299: Synology Calendar
Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
Affected products
- Synology Calendar: before 2.2.2-0532 (fixed in 2.2.2-0532)
Published 2019-04-01. Last modified 2026-06-17.