Pydio

Cells

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.76%
  • Veröffentlicht 04.06.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:24

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.

Exploit
  • EPSS 2.35%
  • Veröffentlicht 04.06.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:24

The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. The update process involves downloading the updated binary file from a URL indicat...

Exploit
  • EPSS 1.45%
  • Veröffentlicht 04.06.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:24

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web app...

Exploit
  • EPSS 1.68%
  • Veröffentlicht 04.06.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:23

Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This console provides an administrator user with the possibility of changing several settings, including t...

  • EPSS 1.66%
  • Veröffentlicht 20.06.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:47

Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.

  • EPSS 0.93%
  • Veröffentlicht 20.06.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:47

Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.

  • EPSS 1.12%
  • Veröffentlicht 20.06.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:47

Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.