PT-2020-13294 · Pydio · Pydio Cells
Published
2020-06-05
·
Updated
2020-06-12
·
CVE-2020-12849
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pydio Cells version 2.0.4
Description
The issue allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated URL by any unauthenticated or authenticated user.
Recommendations
For Pydio Cells version 2.0.4, consider restricting access to profile image uploads to prevent unauthorized users from accessing sensitive information. As a temporary workaround, consider disabling the profile image upload feature until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pydio Cells