Vulnerabilities > Pydio > Cells > 1.2.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-08 | CVE-2023-32750 | Server-Side Request Forgery (SSRF) vulnerability in Pydio Cells Pydio Cells through 4.1.2 allows SSRF. | 6.5 |
2023-06-08 | CVE-2023-32751 | Cross-site Scripting vulnerability in Pydio Cells Pydio Cells through 4.1.2 allows XSS. | 5.4 |
2023-06-08 | CVE-2023-32749 | Incorrect Authorization vulnerability in Pydio Cells Pydio Cells allows users by default to create so-called external users in order to share files with them. | 8.8 |
2019-06-20 | CVE-2019-12903 | Information Exposure Through an Error Message vulnerability in Pydio Cells Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information. | 4.3 |
2019-06-20 | CVE-2019-12902 | Incomplete Cleanup vulnerability in Pydio Cells Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. | 6.5 |
2019-06-20 | CVE-2019-12901 | Path Traversal vulnerability in Pydio Cells Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation. | 8.8 |