Cross-Site Scripting in Pydio Cells by Pydio
CVE-2020-12853
6.1MEDIUM
What is CVE-2020-12853?
Pydio Cells version 2.0.4 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows a malicious user to upload or create files containing malicious HTML and JavaScript code. This code can be executed in the context of other users accessing these files, potentially compromising their security and privacy. Users are advised to ensure they apply proper security measures, such as input validation and sanitization, to mitigate the risks associated with this vulnerability. For further details, refer to the advisories from Core Security and Packet Storm Security.
