Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| synology / beestation_os | 1.0 | 1.0.x |
| synology / beestation_os | 1.0-65145 | 1.0-65145.x |
| synology / beestation_os | 1.0-65149 | 1.0-65149.x |
| synology / beestation_os | 1.0-65162 | 1.0-65162.x |
| synology / beestation_os | 1.0.1-65210 | 1.0.1-65210.x |
| synology / beestation_os | 1.0.2-65233 | 1.0.2-65233.x |
| synology / beestation_os | 1.0.2-65235 | 1.0.2-65235.x |
| synology / beestation_os | 1.1 | 1.1.x |
| synology / beestation_os | 1.1-65373 | 1.1-65373.x |
| synology / diskstation_manager | 7.1 | 7.1.1-42962-7 |
| synology / diskstation_manager | 7.2 | 7.2-64570-4 |
| synology / diskstation_manager | 7.2.1-69057 | 7.2.1-69057-6 |
| synology / diskstation_manager | 7.2.2 | 7.2.2-72806-1 |