A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Storage_manager | Synology | * | 1.0.1-1100 (excluding) |