← Back

CVE-2019-10049

nvd nist
Published: May 31, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.1 / Impact: 5.2
Source: NVD

Description

It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).

Affected (1)

Products: Pydio: Pydio
1 product
Pydio
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.2.2

References (2)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.