PT-2024-24838 · Synology · Photo Station

Nemar Nil

·

Published

2024-11-22

·

Updated

2024-11-22

·

CVE-2024-32767

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Photo Station versions prior to 6.4.3
Description A cross-site scripting (XSS) vulnerability has been reported. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Photo Station until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-32767

Affected Products

Photo Station