CVE-2018-13282: Synology Photo Station

Medium severity, CVSS 6.3. EPSS: 1% chance of exploitation in the next 30 days.

Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

Affected products

  • Synology Photo Station: from 6.3, before 6.3-2976 (fixed in 6.3-2976); from 6.8, before 6.8.7-3481 (fixed in 6.8.7-3481)

Published 2018-10-31. Last modified 2026-06-17.