CVE-2017-12071: SSRF
Published Sep 8, 2017
·Updated
Server-side request forgery (SSRF) vulnerability in fileupload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
Affected Software
2 affected components
Synology Photo Station<=6.3-2967
Synology Photo Station<=6.7.3-3432
Event History
Sep 8, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12071?
CVE-2017-12071 has a high severity rating due to its potential for exploitation via server-side request forgery.
2
How do I fix CVE-2017-12071?
To fix CVE-2017-12071, update Synology Photo Station to version 6.7.4-3433 or later, or 6.3-2968 or later.
3
What are the risks of CVE-2017-12071?
The risks of CVE-2017-12071 include unauthorized access to local files on the server by remote authenticated users.
4
Who is affected by CVE-2017-12071?
Users of Synology Photo Station versions prior to 6.7.4-3433 and 6.3-2968 are affected by CVE-2017-12071.
5
What type of vulnerability is CVE-2017-12071?
CVE-2017-12071 is classified as a server-side request forgery (SSRF) vulnerability.