PT-2020-13292 · Pydio · Pydio Cells
Published
2020-06-04
·
Updated
2021-07-21
·
CVE-2020-12847
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pydio Cells version 2.0.4
Description
The Pydio Cells web application has an administrative console named "Cells Console" that allows users with an administrator role to change settings, including the application's mailer configuration. When the "sendmail" option is selected, the user can edit the full path to the sendmail binary. Since there is no restriction on editing this value, an authenticated administrator user could force the web application to execute any arbitrary binary. This could potentially lead to exploitation by an attacker with administrator privileges.
Recommendations
For Pydio Cells version 2.0.4, as a temporary workaround, consider restricting access to the mailer configuration settings in the Cells Console to minimize the risk of exploitation. Avoid using the "sendmail" option until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pydio Cells