First published: Thu Jun 04 2020(Updated: )
Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pydio Cells | =2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12853 is a vulnerability in Pydio Cells 2.0.4 that allows for cross-site scripting (XSS) attacks.
The severity of CVE-2020-12853 is medium, with a CVSS severity score of 6.1.
CVE-2020-12853 allows a malicious user to upload or create a file containing potentially malicious HTML and JavaScript code to personal folders or accessible cells.
To fix CVE-2020-12853, upgrade to a version of Pydio Cells that is not affected by this vulnerability, or apply any available patches or security updates.
Yes, you can find more information about CVE-2020-12853 in the following references: [Reference 1](http://packetstormsecurity.com/files/158002/Pydio-Cells-2.0.4-XSS-File-Write-Code-Execution.html) and [Reference 2](https://www.coresecurity.com/core-labs/advisories/pydio-cells-204-multiple-vulnerabilities).