CVE-2023-2980: Abstrium Pydio Cells User Creation resource injection
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230212.
Other sources
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230212.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2980?
CVE-2023-2980 is classified as a critical vulnerability.
What component is affected by CVE-2023-2980?
CVE-2023-2980 affects the User Creation Handler component in Abstrium Pydio Cells.
How can CVE-2023-2980 be exploited?
CVE-2023-2980 can be exploited remotely through improper control of resource identifiers.
How do I fix CVE-2023-2980?
To fix CVE-2023-2980, upgrade to Pydio Cells version 4.2.1 or later.
Which versions of Pydio Cells are affected by CVE-2023-2980?
CVE-2023-2980 affects Pydio Cells version 4.2.0 and earlier.