PT-2020-13292 · Pydio · Pydio Cells

Published

2020-06-04

·

Updated

2021-07-21

·

CVE-2020-12847

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pydio Cells version 2.0.4
Description The Pydio Cells web application has an administrative console named "Cells Console" that allows users with an administrator role to change settings, including the application's mailer configuration. When the "sendmail" option is selected, the user can edit the full path to the sendmail binary. Since there is no restriction on editing this value, an authenticated administrator user could force the web application to execute any arbitrary binary. This could potentially lead to exploitation by an attacker with administrator privileges.
Recommendations For Pydio Cells version 2.0.4, as a temporary workaround, consider restricting access to the mailer configuration settings in the Cells Console to minimize the risk of exploitation. Avoid using the "sendmail" option until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-12847

Affected Products

Pydio Cells