PoC Index

CVE-2018-14772

HIGH 9.0EPSS 6.6%

Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.

CVSS v3.0
7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
6.57% chance of exploitation in the next 30 days, 93th percentile
Published
2018-10-16
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related