CVE-2019-11821: SQL Injection
Published Jun 30, 2019
·Updated
SQL injection vulnerability in synophotocsPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.
Affected Software
2 affected components
Synology Photo Station>=6.3<6.3-2977
Synology Photo Station>=6.8<6.8.11-3489
Event History
Jun 30, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-11821?
CVE-2019-11821 is a SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station.
2
How severe is CVE-2019-11821?
CVE-2019-11821 has a severity rating of 9.8 (critical).
3
How does CVE-2019-11821 affect Synology Photo Station?
CVE-2019-11821 affects Synology Photo Station versions before 6.8.11-3489 and before 6.3-2977.
4
What is the impact of CVE-2019-11821?
CVE-2019-11821 allows remote attackers to execute arbitrary SQL commands via the type parameter.
5
How do I fix CVE-2019-11821?
To fix CVE-2019-11821, users should upgrade to Synology Photo Station version 6.8.11-3489 or 6.3-2977.