Vulnerabilities > Pydio > Cells
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-06-04 | CVE-2020-12852 | Improper Input Validation vulnerability in Pydio Cells 2.0.4 The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. | 8.5 |
2020-06-04 | CVE-2020-12851 | Information Exposure vulnerability in Pydio Cells 2.0.4 Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. | 5.5 |
2020-06-04 | CVE-2020-12847 | Improper Input Validation vulnerability in Pydio Cells 2.0.4 Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. | 6.5 |
2019-06-20 | CVE-2019-12903 | Information Exposure vulnerability in Pydio Cells Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information. | 4.0 |
2019-06-20 | CVE-2019-12902 | Information Exposure vulnerability in Pydio Cells Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. | 4.0 |
2019-06-20 | CVE-2019-12901 | Path Traversal vulnerability in Pydio Cells Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation. | 6.5 |