CVE-2018-8925: CSRF
Published Jun 8, 2018
·Updated
Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attackers to hijack the authentication of administrators via the (1) username, (2) password, (3) admin, (4) action, (5) uid, or (6) modifyadmin parameter.
Affected Software
2 affected components
Synology Photo Station>=6.3-2944<6.3-2975
Synology Photo Station>=6.8.0-3456<6.8.5-3471
Event History
Jun 8, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-8925.
2
What is the severity of CVE-2018-8925?
The severity of CVE-2018-8925 is high with a severity value of 8.8.
3
What is the affected software for CVE-2018-8925?
The affected software for CVE-2018-8925 is Synology Photo Station before 6.8.5-3471 and before 6.3-2975.
4
What is the CWE ID for CVE-2018-8925?
The CWE ID for CVE-2018-8925 is CWE-352.
5
How can I fix CVE-2018-8925?
To fix CVE-2018-8925, update Synology Photo Station to version 6.8.5-3471 or 6.3-2975.