CVE-2023-32749

HIGH

Pydio Cells < 3.0.12 - Incorrect Authorization

Title source: rule

Description

Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.

Exploits (3)

exploitdb WORKING POC
by RedTeam Pentesting GmbH · textwebappsgo
https://www.exploit-db.com/exploits/51496
nomisec WORKING POC
by alaeddine03 · poc
https://github.com/alaeddine03/CVE-2023-32749-PoC
nomisec WORKING POC
by xcr-19 · poc
https://github.com/xcr-19/CVE-2023-32749

Scores

CVSS v3 8.8
EPSS 0.4736
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
pydio/cells < 3.0.12
Published Jun 08, 2023
Tracked Since Feb 18, 2026