Path Traversal Vulnerability in Synology Photo Station by Synology
CVE-2021-29091
7.7HIGH
Summary
A Path Traversal vulnerability exists in the file management component of Synology Photo Station prior to version 6.8.14-3500. This flaw allows remote authenticated users to exploit improper limitations on file paths, enabling them to write arbitrary files onto the server. Malicious entities could leverage this vulnerability through unspecified methods, posing serious risks to data integrity and security.
Affected Version(s)
Synology Photo Station < 6.8.14-3500
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved