6.5

CVE-2021-41325

Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PydioCells Version2.2.9 SwEdition-
PydioCells Version2.2.9 SwEditionenterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.616
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://charonv.net/Pydio-Broken-Access-Control/
Third Party Advisory
https://github.com/pydio/cells/releases/tag/v2.2.12
Third Party Advisory
Release Notes
https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212
Vendor Advisory
Product