First published: Tue Mar 17 2020(Updated: )
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pydio Cells | <8.2.4 | |
Pydio Cells | <8.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20453 is a vulnerability found in Pydio Core and Pydio Enterprise before version 8.2.4, allowing authenticated users to inject objects and achieve remote code execution.
CVE-2019-20453 has a severity rating of 8.8 (high).
Pydio Core and Pydio Enterprise versions before 8.2.4 are affected by CVE-2019-20453.
An attacker with basic privileges can exploit CVE-2019-20453 by injecting objects and achieving remote code execution.
Yes, you can find references for CVE-2019-20453 at the following links: [Reference 1](https://pydio.com/en/community/releases/pydio-core/pydio-core-824-security-release), [Reference 2](https://www.certilience.fr/2020/03/cve-2019-20453-vulnerabilite-php-object-injection-pydio-core/).