CVE-2018-8927: Synology Calendar
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter.
Affected products
- Synology Calendar: before 2.1.2-0511 (fixed in 2.1.2-0511)
Published 2018-06-14. Last modified 2026-06-17.