CVE-2019-11821SQL Injection in Synology Photo Station

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
CNA7.3
EPSS
0.6%
top 31.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 24

Description

SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5synology/photo_stationunspecified6.8.11-3489+1
NVDsynology/photo_station6.36.3-2977+1

🔴Vulnerability Details

2
GHSA
GHSA-6wpv-3286-cf7f: SQL injection vulnerability in synophoto_csPhotoDB2022-05-24
CVEList
CVE-2019-11821: SQL injection vulnerability in synophoto_csPhotoDB2019-06-30
CVE-2019-11821 — SQL Injection in Synology | cvebase