Security Advisory

CVE-2019-12901

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-06-19 23:05:47
Last updated 2024-08-04 23:32:55
Assigner mitre
State PUBLISHED

Description

Pydio Cells before 1.5.0 fails to neutralize ../ elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.