Synology Photo Station vulnerabilities
33 known vulnerabilities affecting synology/photo_station.
Total CVEs
33
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH15MEDIUM12
Vulnerabilities
Page 1 of 2
CVE-2022-22681HIGHCVSS 7.5fixed in 6.8.16-3506≥ unspecified, < 6.8.16-35062022-07-06
CVE-2022-22681 [HIGH] CWE-384 CVE-2022-22681: Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.
cvelistv5nvd
CVE-2021-29089CRITICALCVSS 9.8≥ 6.8, < 6.8.14-35002021-06-02
CVE-2021-29089 [CRITICAL] CWE-89 CVE-2021-29089: Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability i
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.
nvd
CVE-2021-29090HIGHCVSS 7.2≥ 6.8, < 6.8.14-35002021-06-02
CVE-2021-29090 [HIGH] CWE-89 CVE-2021-29090: Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability i
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.
nvd
CVE-2021-29091MEDIUMCVSS 6.5≥ 6.8, < 6.8.14-35002021-06-02
CVE-2021-29091 [MEDIUM] CWE-22 CVE-2021-29091: Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary files via unspecified vectors.
nvd
CVE-2021-29092HIGHCVSS 8.8≥ 6.8, < 6.8.14-35002021-06-01
CVE-2021-29092 [HIGH] CWE-434 CVE-2021-29092: Unrestricted upload of file with dangerous type vulnerability in file management component in Synolo
Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary code via unspecified vectors.
nvd
CVE-2019-11821CRITICALCVSS 9.8≥ 6.3, < 6.3-2977≥ 6.8, < 6.8.11-3489+2 more2019-06-30
CVE-2019-11821 [CRITICAL] CWE-89 CVE-2019-11821: SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489
SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.
cvelistv5nvd
CVE-2019-11822MEDIUMCVSS 6.5≥ 6.3, < 6.3-2977≥ 6.8, < 6.8.11-3489+2 more2019-06-30
CVE-2019-11822 [MEDIUM] CWE-23 CVE-2019-11822: Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
cvelistv5nvd
CVE-2018-13282MEDIUMCVSS 6.3≥ 6.3, < 6.3-2976≥ 6.8, < 6.8.7-3481+1 more2018-10-31
CVE-2018-13282 [MEDIUM] CWE-384 CVE-2018-13282: Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
cvelistv5nvd
CVE-2018-8925HIGHCVSS 8.8≥ 6.3-2944, < 6.3-2975≥ 6.8.0-3456, < 6.8.5-3471+2 more2018-06-08
CVE-2018-8925 [HIGH] CWE-352 CVE-2018-8925: Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6
Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) username, (2) password, (3) admin, (4) action, (5) uid, or (6) modify_admin parameter.
cvelistv5nvd
CVE-2018-8926HIGHCVSS 8.8≥ 6.3-2958, ≤ 6.3-2975≥ 6.8.0-3456, < 6.8.5-3471+2 more2018-06-08
CVE-2018-8926 [HIGH] CWE-625 CVE-2018-8926: Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.
cvelistv5nvd
CVE-2017-16772HIGHCVSS 8.8≥ 6.8, < 6.8.3-3463≥ 6.3, < 6.3-2971+2 more2018-03-22
CVE-2017-16772 [HIGH] CWE-434 CVE-2017-16772: Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station be
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
cvelistv5nvd
CVE-2017-16771MEDIUMCVSS 6.1≥ 6.8, < 6.8.3-3463≥ 6.3, < 6.3-2971+2 more2018-03-22
CVE-2017-16771 [MEDIUM] CWE-79 CVE-2017-16771: Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 a
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
cvelistv5nvd
CVE-2017-16769MEDIUMCVSS 5.3v6.8.1-34582018-02-23
CVE-2017-16769 [MEDIUM] CWE-359 CVE-2017-16769: Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 a
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
nvd
CVE-2017-12072MEDIUMCVSS 5.4fixed in 6.8.0-3456vbefore 6.8.0-34562017-12-20
CVE-2017-12072 [MEDIUM] CWE-79 CVE-2017-12072: Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.
cvelistv5nvd
CVE-2017-12079HIGHCVSS 7.5≥ 6.8, < 6.8.1-3458≥ 6.3, < 6.3-2970+2 more2017-12-04
CVE-2017-12079 [HIGH] CWE-552 CVE-2017-12079: Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo St
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
cvelistv5nvd
CVE-2017-12080MEDIUMCVSS 5.3≥ 6.3, < 6.3-2970≥ 6.8, < 6.8.1-3458+2 more2017-12-04
CVE-2017-12080 [MEDIUM] CWE-200 CVE-2017-12080: An information exposure vulnerability in default HTTP configuration file in Synology Photo Station b
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.
cvelistv5nvd
CVE-2017-11161CRITICALCVSS 9.8≤ 6.3-2967≤ 6.7.3-34322017-09-08
CVE-2017-11161 [CRITICAL] CWE-89 CVE-2017-11161: Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allo
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.
nvd
CVE-2017-12071MEDIUMCVSS 6.5≤ 6.3-2967≤ 6.7.3-34322017-09-08
CVE-2017-12071 [MEDIUM] CWE-918 CVE-2017-12071: Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
nvd
CVE-2017-11162MEDIUMCVSS 6.5≤ 6.3-2967≤ 6.7.3-34322017-09-08
CVE-2017-11162 [MEDIUM] CWE-22 CVE-2017-11162: Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-
Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.
nvd
CVE-2017-9555MEDIUMCVSS 5.4≤ 6.6.3-33472017-08-24
CVE-2017-9555 [MEDIUM] CWE-79 CVE-2017-9555: Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
nvd
1 / 2Next →