A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230211.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://vuldb.com/?id.230211 | third party advisory vdb entry permissions required technical description |
https://vuldb.com/?ctiid.230211 | signature third party advisory vdb entry permissions required |
https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421 | patch release notes |
https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be | third party advisory exploit |