CVE-2018-14772

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/10/2018
Last modified:
24/08/2020

Description

Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pydio:pydio:*:*:*:*:*:*:*:* 4.2.1 (including) 8.2.1 (including)


References to Advisories, Solutions, and Tools