First published: Sun Jun 30 2019(Updated: )
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Moments | <1.3.0-0691 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11826 has been rated as a high severity vulnerability due to its potential for remote file upload exploits.
To fix CVE-2019-11826, update Synology Moments to version 1.3.0-0691 or later.
Remote authenticated users of Synology Moments versions prior to 1.3.0-0691 are affected by CVE-2019-11826.
CVE-2019-11826 can allow authenticated users to upload arbitrary files, posing a risk of unauthorized access or system compromise.
Yes, CVE-2019-11826 is exploitable by remote authenticated users, which could include attackers with access to the affected system.