Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
2024-11-15T11:15:09.750
2025-09-16T06:16:04.327
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | photos | < 1.6.2-0720 | Yes |
| Operating System | synology | diskstation_manager | 7.2 | No |
| Application | synology | beephotos | < 1.1.0-10053 | Yes |
| Operating System | synology | beestation_os | 1.1 | No |
| Application | synology | beephotos | < 1.0.2-10026 | Yes |
| Operating System | synology | beestation_os | 1.0 | No |
| Application | synology | photos | < 1.7.0-0795 | Yes |
| Operating System | synology | diskstation_manager | 7.2.2 | No |