RULE(RULE ID:336528)

Rule General Information
Release Date: 2022-04-20
Rule Name: Synology PhotoStation Arbitrary File Upload Vulnerability (CVE-2019-11822)
Severity:
CVE ID:
Rule Protection Details
Description: Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://www.synology.com/security/advisory/Synology_SA_19_01
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.synology.com/security/advisory/Synology_SA_19_01