CVE-2020-12851
- EPSS 1.25%
- Veröffentlicht 04.06.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:24
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web app...
CVE-2020-12852
- EPSS 1.41%
- Veröffentlicht 04.06.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:24
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. The update process involves downloading the updated binary file from a URL indicat...
CVE-2020-12853
- EPSS 0.24%
- Veröffentlicht 04.06.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:24
Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.
CVE-2019-12901
- EPSS 0.69%
- Veröffentlicht 20.06.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:47
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
CVE-2019-12902
- EPSS 0.31%
- Veröffentlicht 20.06.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:47
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
CVE-2019-12903
- EPSS 0.23%
- Veröffentlicht 20.06.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:47
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.