SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.Referenceshttps://www.synology.com/en-global/support/security/Synology_SA_18_04