CVE-2017-16772: Input Validation
Published Mar 22, 2018
·Updated
Improper input validation vulnerability in SYNOPHOTOFlickrMultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the progid parameter.
Affected Software
2 affected components
Synology Photo Station>=6.8<6.8.3-3463
Synology Photo Station>=6.3<6.3-2971
Event History
Mar 22, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16772.
2
What is the severity level of CVE-2017-16772?
The severity level of CVE-2017-16772 is high.
3
What is the affected software?
The affected software is Synology Photo Station before 6.8.3-3463 and before 6.3-2971.
4
How does CVE-2017-16772 affect the affected software?
CVE-2017-16772 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
5
How can I fix CVE-2017-16772?
To fix CVE-2017-16772, update Synology Photo Station to version 6.8.3-3463 or 6.3-2971 or later.