Synology · Synology Photo Station · CVE-2018-8925
**Name of the Vulnerable Software and Affected Versions**
Synology Photo Station versions prior to 6.8.5-3471
Synology Photo Station versions prior to 6.3-2975
**Description**
A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of administrators. This can be achieved via the `username`, `password`, `admin`, `action`, `uid`, or `modify admin` parameter.
**Recommendations**
For Synology Photo Station versions prior to 6.8.5-3471, update to version 6.8.5-3471 or later.
For Synology Photo Station versions prior to 6.3-2975, update to version 6.3-2975 or later.