Vulnerabilities > Pydio > Cells

DATE CVE VULNERABILITY TITLE RISK
2020-06-04 CVE-2020-12852 Improper Input Validation vulnerability in Pydio Cells 2.0.4
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package.
network
pydio CWE-20
8.5
2020-06-04 CVE-2020-12851 Information Exposure vulnerability in Pydio Cells 2.0.4
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application.
network
low complexity
pydio CWE-200
5.5
2020-06-04 CVE-2020-12847 Improper Input Validation vulnerability in Pydio Cells 2.0.4
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role.
network
low complexity
pydio CWE-20
6.5
2019-06-20 CVE-2019-12903 Information Exposure vulnerability in Pydio Cells
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.
network
low complexity
pydio CWE-200
4.0
2019-06-20 CVE-2019-12902 Information Exposure vulnerability in Pydio Cells
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion.
network
low complexity
pydio CWE-200
4.0
2019-06-20 CVE-2019-12901 Path Traversal vulnerability in Pydio Cells
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
network
low complexity
pydio CWE-22
6.5