Vulnerabilities > Pydio > Cells > 2.0.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-08 | CVE-2023-32750 | Server-Side Request Forgery (SSRF) vulnerability in Pydio Cells Pydio Cells through 4.1.2 allows SSRF. | 6.5 |
2023-06-08 | CVE-2023-32751 | Cross-site Scripting vulnerability in Pydio Cells Pydio Cells through 4.1.2 allows XSS. | 5.4 |
2023-06-08 | CVE-2023-32749 | Incorrect Authorization vulnerability in Pydio Cells Pydio Cells allows users by default to create so-called external users in order to share files with them. | 8.8 |
2020-06-11 | CVE-2020-12850 | Improper Privilege Management vulnerability in Pydio Cells 2.0.4 The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. | 7.0 |
2020-06-05 | CVE-2020-12849 | Cross-site Scripting vulnerability in Pydio Cells 2.0.4 Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. | 5.4 |
2020-06-05 | CVE-2020-12848 | Improper Authentication vulnerability in Pydio Cells 2.0.4 In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in the backend with a random username. | 5.4 |
2020-06-04 | CVE-2020-12853 | Cross-site Scripting vulnerability in Pydio Cells 2.0.4 Pydio Cells 2.0.4 allows XSS. | 6.1 |
2020-06-04 | CVE-2020-12852 | Improper Input Validation vulnerability in Pydio Cells 2.0.4 The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. | 6.8 |
2020-06-04 | CVE-2020-12851 | Path Traversal vulnerability in Pydio Cells 2.0.4 Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. | 8.1 |
2020-06-04 | CVE-2020-12847 | Unspecified vulnerability in Pydio Cells 2.0.4 Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. | 7.2 |