CVE-2021-29090: SQL Injection
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29090?
The severity of CVE-2021-29090 is critical with a severity value of 7.2.
What is the vulnerability description of CVE-2021-29090?
CVE-2021-29090 is an SQL Injection vulnerability in the PHP component in Synology Photo Station before 6.8.14-3500, allowing remote authenticated users to execute arbitrary SQL commands.
Which software is affected by CVE-2021-29090?
Synology Photo Station versions before 6.8.14-3500 are affected by CVE-2021-29090.
How can an attacker exploit CVE-2021-29090?
An attacker can exploit CVE-2021-29090 by using unspecified vectors to execute arbitrary SQL commands.
Is there a fix available for CVE-2021-29090?
Yes, a fix is available for CVE-2021-29090. Please refer to the Synology Security Advisory Synology_SA_20_20 for more information.