CVE-2018-14772
HIGH 9.0EPSS 6.6%
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.
- CVSS v3.0
- 7.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 6.57% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2018-10-16
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- killvxk/CVE-2018-147721★ · 2018-11-01