First published: Fri Sep 08 2017(Updated: )
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | <=6.3-2967 | |
Synology Photo Station | <=6.7.3-3432 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12071 has a high severity rating due to its potential for exploitation via server-side request forgery.
To fix CVE-2017-12071, update Synology Photo Station to version 6.7.4-3433 or later, or 6.3-2968 or later.
The risks of CVE-2017-12071 include unauthorized access to local files on the server by remote authenticated users.
Users of Synology Photo Station versions prior to 6.7.4-3433 and 6.3-2968 are affected by CVE-2017-12071.
CVE-2017-12071 is classified as a server-side request forgery (SSRF) vulnerability.