CVE-2024-12923: Photo Station
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version: Photo Station 6.4.5 ( 2025/01/02 ) and later
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12923?
CVE-2024-12923 is classified as a cross-site scripting (XSS) vulnerability with potentially high severity due to its ability to expose application data.
How do I fix CVE-2024-12923?
To fix CVE-2024-12923, update your Synology Photo Station to version 6.4.5 or later.
Who is affected by CVE-2024-12923?
CVE-2024-12923 affects users of Synology Photo Station versions prior to 6.4.5.
What are the potential impacts of CVE-2024-12923?
The potential impacts of CVE-2024-12923 include unauthorized data access and the ability for attackers to bypass security mechanisms.
Can CVE-2024-12923 be exploited remotely?
Yes, CVE-2024-12923 can be exploited remotely if an attacker gains access to a user account.