vletroye / SynoPackages

Various Synology Packages built with Mods Packager
126 stars 24 forks source link

Vulnerability warning for MODS_WebConsole #45

Open Nriver opened 2 years ago

Nriver commented 2 years ago

The default configuration in MODS_WebConsole could cause remote code execution. This page: http://YOUR_SYNOLOGY_IP:5000/webman/3rdparty/MODS_WebConsole/index.php is exposed without proper authentication. It's extremely dangerous for someone happens to have his synology accessable over the Internet.