Cross-Site Scripting Vulnerability in Pydio Cells by Pydio
CVE-2023-32751

5.4MEDIUM

Key Information:

Vendor

Pydio

Status
Vendor
CVE Published:
8 June 2023

What is CVE-2023-32751?

Pydio Cells versions up to 4.1.2 expose a cross-site scripting vulnerability due to hardcoded secrets in JavaScript that are utilized for generating presigned URLs. An attacker can exploit this weakness by uploading an HTML file and crafting a specific download URL that serves the file inline. This allows the embedded JavaScript within the uploaded HTML file to execute in the context of the user’s browser when accessed, potentially compromising user data and session integrity. Pydio users should ascertain their version and apply necessary mitigations to prevent exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.