PT-2020-10458 · Pydio+1 · Pydio Enterprise+2

Published

2020-03-17

·

Updated

2020-08-24

·

CVE-2019-20453

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pydio Core versions prior to 8.2.4 Pydio Enterprise versions prior to 8.2.4
Description A PHP object injection issue is present in the page plugins/uploader.http/HttpDownload.php. This allows an authenticated user with basic privileges to inject objects and achieve remote code execution.
Recommendations For Pydio Core versions prior to 8.2.4, update to version 8.2.4 or later. For Pydio Enterprise versions prior to 8.2.4, update to version 8.2.4 or later. As a temporary workaround, consider restricting access to the plugins/uploader.http/HttpDownload.php page to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20453

Affected Products

Php
Pydio Core
Pydio Enterprise