CVE-2018-20718: Critical severity pydio cells vulnerability
Published Jan 15, 2019
·Updated
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.
Affected Software
1 affected component
Pydio Pydio<8.2.2
Event History
Jan 15, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Pydio vulnerability?
The vulnerability ID for this Pydio vulnerability is CVE-2018-20718.
2
What is the severity of CVE-2018-20718?
The severity of CVE-2018-20718 is critical.
3
What is the affected software for CVE-2018-20718?
The affected software for CVE-2018-20718 is Pydio version up to and excluding 8.2.2.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-502.
5
How can an attacker exploit CVE-2018-20718?
An attacker can exploit CVE-2018-20718 by using PHP Object Injection through the $phpserial$a:0:{} syntax to store a preference.