CVE-2019-12901
EUVD-2019-447920.06.2019, 00:15
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pydio | cells | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions
References