CVE-2019-20453: High severity pydio cells vulnerability
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20453?
CVE-2019-20453 is a vulnerability found in Pydio Core and Pydio Enterprise before version 8.2.4, allowing authenticated users to inject objects and achieve remote code execution.
How severe is CVE-2019-20453?
CVE-2019-20453 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2019-20453?
Pydio Core and Pydio Enterprise versions before 8.2.4 are affected by CVE-2019-20453.
How can an attacker exploit CVE-2019-20453?
An attacker with basic privileges can exploit CVE-2019-20453 by injecting objects and achieving remote code execution.
Are there any references available for CVE-2019-20453?
Yes, you can find references for CVE-2019-20453 at the following links: [Reference 1](https://pydio.com/en/community/releases/pydio-core/pydio-core-824-security-release), [Reference 2](https://www.certilience.fr/2020/03/cve-2019-20453-vulnerabilite-php-object-injection-pydio-core/).