Cross-Site Scripting in Pydio Cells by Pydio
CVE-2020-12853

6.1MEDIUM

Key Information:

Vendor

Pydio

Status
Vendor
CVE Published:
4 June 2020

What is CVE-2020-12853?

Pydio Cells version 2.0.4 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows a malicious user to upload or create files containing malicious HTML and JavaScript code. This code can be executed in the context of other users accessing these files, potentially compromising their security and privacy. Users are advised to ensure they apply proper security measures, such as input validation and sanitization, to mitigate the risks associated with this vulnerability. For further details, refer to the advisories from Core Security and Packet Storm Security.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.