SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.
2019-06-30T15:15:09.603
2024-11-21T04:21:49.913
Modified
CVSSv3.1: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | photo_station | < 6.3-2977 | Yes |
| Application | synology | photo_station | < 6.8.11-3489 | Yes |