PT-2020-13294 · Pydio · Pydio Cells

Published

2020-06-05

·

Updated

2020-06-12

·

CVE-2020-12849

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pydio Cells version 2.0.4
Description The issue allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated URL by any unauthenticated or authenticated user.
Recommendations For Pydio Cells version 2.0.4, consider restricting access to profile image uploads to prevent unauthorized users from accessing sensitive information. As a temporary workaround, consider disabling the profile image upload feature until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12849

Affected Products

Pydio Cells