PT-2024-1625 · Synology · Photo Station

Alan Li

+1

·

Published

2024-02-02

·

Updated

2024-02-07

·

CVE-2023-47561

CVSS v3.1

5.5

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Photo Station versions prior to 6.4.2
Description A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. The issue is related to the lack of protection measures for the web page structure, which could allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 6.4.2, update to Photo Station 6.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Photo Station application until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-01292
CVE-2023-47561

Affected Products

Photo Station