CVE-2018-13282: Synology Photo Station
Medium severity, CVSS 6.3. EPSS: 1% chance of exploitation in the next 30 days.
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
Affected products
- Synology Photo Station: from 6.3, before 6.3-2976 (fixed in 6.3-2976); from 6.8, before 6.8.7-3481 (fixed in 6.8.7-3481)
Published 2018-10-31. Last modified 2026-06-17.