C&T-SA-24:19 C&T Photos (PWN2OWN 2024)
Abstract
A vulnerability allows remote attackers to execute arbitrary code.
The vulnerability reported by PWN2OWN 2024 (ZDI-CAN-25623) has been addressed.
Affected Products
Product |
Severity |
Fixed Release Availability |
C&T Photos 1.7 for DSM 7.2 |
Critical |
Upgrade to 1.7.0-0795 or above. |
C&T Photos 1.6 for DSM 7.2 |
Critical |
Upgrade to 1.6.2-0720 or above. |