AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-32751

MEDIUM · CVSS 5.4 EPSS 2.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-08 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.4. It affects Java.

CVE
CVE-2023-32751
Severity
MEDIUM
CVSS
5.4
EPSS
2.94%
Java

Original NVD Description

Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets used to sign these URLs are hardcoded and exposed through the JavaScript files of the web application. Therefore, it is possible to generate valid signatures for arbitrary download URLs. By uploading an HTML file and modifying the download URL to serve the file inline instead of as an attachment, any included JavaScript code is executed when the URL is opened in a browser, leading to a cross-site scripting vulnerability.

Related CVEs

Other vulnerabilities affecting the same vendor(s)