Pydio Cells before 1.5.0 fails to neutralize ‘../’ elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
Source: NIST
CVE-2019-12901
Security in mind
Pydio Cells before 1.5.0 fails to neutralize ‘../’ elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.
Source: NIST
CVE-2019-12901