Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to impersonate a user and perform actions on behalf of him/her (if the session is still active).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pydio 授权问题漏洞
Vulnerability Description
Pydio(AjaXplorer)是一款基于Web的远程文件管理器。该管理器支持上传和下载文件、在线文件编辑、图片预览等。 Pydio 8.2.2及之前版本中存在安全漏洞。攻击者可利用该漏洞伪造用户并以用户身份执行操作。
CVSS Information
N/A
Vulnerability Type
N/A