Pydio

Cells

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.25%
  • Published 04.06.2020 20:15:11
  • Last modified 21.11.2024 05:00:24

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web app...

Exploit
  • EPSS 1.41%
  • Published 04.06.2020 20:15:11
  • Last modified 21.11.2024 05:00:24

The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. The update process involves downloading the updated binary file from a URL indicat...

Exploit
  • EPSS 0.24%
  • Published 04.06.2020 20:15:11
  • Last modified 21.11.2024 05:00:24

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.

  • EPSS 0.69%
  • Published 20.06.2019 00:15:10
  • Last modified 21.11.2024 04:23:47

Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.

  • EPSS 0.31%
  • Published 20.06.2019 00:15:10
  • Last modified 21.11.2024 04:23:47

Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.

  • EPSS 0.23%
  • Published 20.06.2019 00:15:10
  • Last modified 21.11.2024 04:23:47

Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.