CVE-2019-11822: Path Traversal
Published Jun 30, 2019
·Updated
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
Affected Software
2 affected components
Synology Photo Station>=6.3<6.3-2977
Synology Photo Station>=6.8<6.8.11-3489
Event History
Jun 30, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-11822?
CVE-2019-11822 is a relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977.
2
How does CVE-2019-11822 exploit work?
The vulnerability allows remote attackers to upload arbitrary files via the uploadphoto parameter.
3
What is the severity of CVE-2019-11822?
CVE-2019-11822 has a severity rating of medium (6.5).
4
How can I fix CVE-2019-11822?
To fix CVE-2019-11822, it is recommended to update Synology Photo Station to version 6.8.11-3489 or 6.3-2977.
5
Where can I find more information about CVE-2019-11822?
You can find more information about CVE-2019-11822 in the Synology security advisory Synology_SA_19_01.