Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
2018-10-31T16:29:00.393
2024-11-21T03:46:45.160
Modified
CVSSv3.0: 5.6 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | photo_station | < 6.3-2976 | Yes |
| Application | synology | photo_station | < 6.8.7-3481 | Yes |