CVE-2018-20718
Last modified
CVE-2018-20718 is a vulnerability of currently unknown severity. In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.. EPSS estimates a 3.73% chance of exploitation in the next 30 days.
Description
In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pydio | Pydio | < 8.2.2 |
References
- https://blog.ripstech.com/2018/pydio-unauthenticated-remote-code-execution/Exploit, Third Party Advisory
- https://blog.ripstech.com/2018/pydio-unauthenticated-remote-code-execution/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20718?
How severe is CVE-2018-20718?
How do I fix CVE-2018-20718?
Are you affected by CVE-2018-20718?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
