CVE-2023-32749
CVE-2023-32749
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
n/a · n/aPoCs públicas encontradas — 4
githubgithub.com/alaeddine03/CVE-2023-32749-PoC★ 1githubgithub.com/xcr-19/CVE-2023-32749★ 0cve_referencepacketstormsecurity.com/files/172645/Pydio-Cells-4.1.2-Privilege-Escalation.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/51496não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/172645/Pydio-Cells-4.1.2-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2023/May/18https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyseshttps://www.redteam-pentesting.de/en/advisories/rt-sa-2023-003/-pydio-cells-unauthorised-role-assignments