CVE-2023-32749
46Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 14%
from disclosure to weapon0 days
Published on NVDJun 8
1st PoCMay 31
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/51496unverifiedgithubgithub.com/alaeddine03/CVE-2023-32749-PoC★ 1githubgithub.com/xcr-19/CVE-2023-32749★ 0cve_referencepacketstormsecurity.com/files/172645/Pydio-Cells-4.1.2-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/172645/Pydio-Cells-4.1.2-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2023/May/18https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyseshttps://www.redteam-pentesting.de/en/advisories/rt-sa-2023-003/-pydio-cells-unauthorised-role-assignments