First published: Fri Jun 08 2018(Updated: )
Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | >=6.3-2958<=6.3-2975 | |
Synology Photo Station | >=6.8.0-3456<6.8.5-3471 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-8926.
The title of this vulnerability is Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975.
The severity of CVE-2018-8926 is high with a severity value of 8.8.
Remote authenticated users can exploit this vulnerability by conducting privilege escalation attacks via the fullname parameter.
To fix this vulnerability, update Synology Photo Station to version 6.8.5-3471 or 6.3-2975.