Known Vulnerabilities for Photo Station by Synology
Listed below are 10 of the newest known vulnerabilities associated with "Photo Station" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-22681 | Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attack... | 7.5 - HIGH | 2022-07-06 | 2022-07-14 |
| CVE-2021-29092 | Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6... | 8.8 - HIGH | 2021-06-01 | 2021-06-09 |
| CVE-2021-29091 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in ... | 6.5 - MEDIUM | 2021-06-02 | 2021-06-10 |
| CVE-2021-29090 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synolo... | 7.2 - HIGH | 2021-06-02 | 2021-06-10 |
| CVE-2021-29089 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in ... | 9.8 - CRITICAL | 2021-06-02 | 2021-06-10 |
| CVE-2019-11822 | Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2... | 6.5 - MEDIUM | 2019-06-30 | 2023-01-30 |
| CVE-2019-11821 | SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allow... | 9.8 - CRITICAL | 2019-06-30 | 2023-01-30 |
| CVE-2018-13282 | Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers ... | 6.3 - MEDIUM | 2018-10-31 | 2019-10-09 |
| CVE-2018-8926 | Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-... | 8.8 - HIGH | 2018-06-08 | 2019-10-09 |
| CVE-2018-8925 | Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-... | 8.8 - HIGH | 2018-06-08 | 2019-10-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Photo Station | 6.8.9-3483 | All | All | All |
| Application | Synology | Photo Station | 6.8.8-3482 | All | All | All |
| Application | Synology | Photo Station | 6.8.7-3481 | All | All | All |
| Application | Synology | Photo Station | 6.8.6-3479 | All | All | All |
| Application | Synology | Photo Station | 6.8.5-3471 | All | All | All |
| Application | Synology | Photo Station | 6.8.4-3468 | All | All | All |
| Application | Synology | Photo Station | 6.8.3-3463 | All | All | All |
| Application | Synology | Photo Station | 6.8.2-3461 | All | All | All |
| Application | Synology | Photo Station | 6.8.11-3489 | All | All | All |
| Application | Synology | Photo Station | 6.8.10-3487 | All | All | All |
| Application | Synology | Photo Station | 6.8.1-3458 | All | All | All |
| Application | Synology | Photo Station | 6.8.0-3456 | All | All | All |
| Application | Synology | Photo Station | 6.8 | All | All | All |
| Application | Synology | Photo Station | 6.7.4-3433 | All | All | All |
| Application | Synology | Photo Station | 6.7.3-3432 | All | All | All |
| Application | Synology | Photo Station | 6.7.2-3429 | All | All | All |
| Application | Synology | Photo Station | 6.7.1-3419 | All | All | All |
| Application | Synology | Photo Station | 6.7.0-3414 | All | All | All |
| Application | Synology | Photo Station | 6.6.3-3347 | All | All | All |
| Application | Synology | Photo Station | 6.6.2-3346 | All | All | All |