CVE-2024-40124: XSS
Published Apr 17, 2025
·Updated
Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
Affected Software
2 affected components
Pydio Core<=8.2.5
Pydio Pydio<=8.2.5
Remediation
Event History
Apr 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40124?
CVE-2024-40124 is classified as a medium severity vulnerability due to the potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-40124?
To fix CVE-2024-40124, it is recommended to update Pydio Core to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2024-40124 on users?
The impact of CVE-2024-40124 includes the risk of attackers executing malicious scripts in the context of users' browsers.
4
Is CVE-2024-40124 specific to certain versions of Pydio Core?
Yes, CVE-2024-40124 affects Pydio Core versions up to and including 8.2.5.
5
How can I determine if my Pydio Core installation is affected by CVE-2024-40124?
To determine if your installation is affected by CVE-2024-40124, check the software version against the specified vulnerable versions list.