Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/AntivirusScanner.php: Line 124, scanNow($nodeObject) that can result in An attacker gaining admin access and can then execute arbitrary commands on the underlying OS. This attack appear to be exploitable via The attacker edits the Antivirus Command in the antivirus plugin, and executes the payload by uploading any file within Pydio.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pydio 安全漏洞
Vulnerability Description
Pydio(前称AjaXplorer)是一款基于Web的远程文件管理器。该管理器支持上传和下载文件、在线文件编辑、图片预览等。 Pydio 8.2.1及之前版本在plugins/action.antivirus/AntivirusScanner.php文件的‘scanNow($nodeObject)’参数存在安全漏洞。攻击者可通过在反病毒插件中编辑反病毒命令并执行载荷利用该漏洞获取管理访问权限,从而在底层操作系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A