Arbitrary File Download Vulnerability in Synology Photo Station

Arbitrary File Download Vulnerability in Synology Photo Station

CVE-2017-12071 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.

Learn more about our User Device Pen Test.