CVE-2019-12901

Publication date

2019-06-19 23:05:47

Family

mitre

State

PUBLISHED

Description

Pydio Cells before 1.5.0 fails to neutralize ../ elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.