Vulnerabilities > Pydio > Cells > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-08 CVE-2023-32749 Incorrect Authorization vulnerability in Pydio Cells
Pydio Cells allows users by default to create so-called external users in order to share files with them.
network
low complexity
pydio CWE-863
8.8
2020-06-11 CVE-2020-12850 Improper Privilege Management vulnerability in Pydio Cells 2.0.4
The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4.
local
high complexity
pydio CWE-269
7.0
2020-06-04 CVE-2020-12851 Path Traversal vulnerability in Pydio Cells 2.0.4
Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application.
network
low complexity
pydio CWE-22
8.1
2020-06-04 CVE-2020-12847 Unspecified vulnerability in Pydio Cells 2.0.4
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role.
network
low complexity
pydio
7.2
2019-06-20 CVE-2019-12901 Path Traversal vulnerability in Pydio Cells
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
network
low complexity
pydio CWE-22
8.8