CVE-2019-12901: Path Traversal
Published Jun 19, 2019
·Updated
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
Affected Software
1 affected component
Pydio Cells<1.5.0
Event History
Jun 19, 2019
CVE Published
via MITRE·11:05 PM
Data Sourced
via MITRE·11:05 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-12901.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Pydio Cells before 1.5.0 fails to neutralize ../ elements allowing an attacker with minimum privilege...'.
3
What is the severity level of CVE-2019-12901?
The severity level of CVE-2019-12901 is high.
4
What is the affected software version?
The affected software version is Pydio Cells up to but not including 1.5.0.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker with minimum privilege to upload and delete files/folders in an unprivileged directory, leading to privilege escalation.