Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.synology.com/en-global/support/security/Synology_SA_17_63_Photo_Station | vendor advisory |