Improper Input Validation in Synology Photo Station Affecting Synology Products
CVE-2017-16772
8.8HIGH
What is CVE-2017-16772?
An input validation flaw exists in the SYNOPHOTO_Flickr_MultiUpload feature of Synology Photo Station versions prior to 6.8.3-3463 and 6.3-2971. This vulnerability allows remote authenticated users to exploit the system by injecting arbitrary code through the prog_id parameter. As a result, attackers could potentially gain unauthorized control and execute malicious payloads on affected systems, highlighting the importance of proper input validation in software development.
Affected Version(s)
Photo Station before 6.8.3-3463
Photo Station before 6.3-2971