CVE-2018-8926: High severity Synology Photo Station vulnerability
Published Jun 8, 2018
·Updated
Permissive regular expression vulnerability in synophotodsmuser in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.
Affected Software
2 affected components
Synology Photo Station>=6.3-2958<=6.3-2975
Synology Photo Station>=6.8.0-3456<6.8.5-3471
Event History
Jun 8, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-8926.
2
What is the title of this vulnerability?
The title of this vulnerability is Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975.
3
What is the severity of CVE-2018-8926?
The severity of CVE-2018-8926 is high with a severity value of 8.8.
4
How can remote authenticated users exploit this vulnerability?
Remote authenticated users can exploit this vulnerability by conducting privilege escalation attacks via the fullname parameter.
5
How can I fix this vulnerability?
To fix this vulnerability, update Synology Photo Station to version 6.8.5-3471 or 6.3-2975.