Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20718

Опубликовано: 15 янв. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pydio:pydio:*:*:*:*:*:*:*:*
Версия до 8.2.2 (исключая)

EPSS

Процентиль: 93%
0.09386
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
debian
около 7 лет назад

In Pydio before 8.2.2, an attack is possible via PHP Object Injection ...

CVSS3: 9.8
github
больше 3 лет назад

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.

EPSS

Процентиль: 93%
0.09386
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-502