CVE-2024-10443: OS Command Injection
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10443?
CVE-2024-10443 is considered critical due to its potential for remote code execution.
How do I fix CVE-2024-10443?
To fix CVE-2024-10443, update to Synology BeePhotos version 1.0.2-10026 or later and Synology Photos version 1.6.2-0720 or later.
What products are affected by CVE-2024-10443?
CVE-2024-10443 affects Synology BeePhotos and Synology Photos versions prior to specified fixes.
Can CVE-2024-10443 be exploited remotely?
Yes, CVE-2024-10443 can be exploited remotely, allowing attackers to execute arbitrary code.
What type of vulnerability is CVE-2024-10443?
CVE-2024-10443 is classified as a command injection vulnerability.