Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2021-41324
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete).
0
Attacker Value
Unknown
CVE-2021-41323
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter.
0
Attacker Value
Unknown
CVE-2021-41325
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.)
0