CVE-2020-12849
05.06.2020, 13:15
Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated URL by any unauthenticated or authenticated user.
| Vendor | Product | Version |
|---|---|---|
| pydio | cells | 2.0.4 |
𝑥
= Vulnerable software versions
References