CVE-2021-41325
Estado: ModificadaMedia (6.5)—
Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.)
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.15%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- https://charonv.net/Pydio-Broken-Access-Control/
- https://github.com/pydio/cells/releases/tag/v2.2.12
- https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212
- https://charonv.net/Pydio-Broken-Access-Control/
- https://github.com/pydio/cells/releases/tag/v2.2.12
- https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-41325",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-09-30T19:15:07.513",
"references": [
{
"url": "https://charonv.net/Pydio-Broken-Access-Control/",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/pydio/cells/releases/tag/v2.2.12",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://charonv.net/Pydio-Broken-Access-Control/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/pydio/cells/releases/tag/v2.2.12",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.)"
},
{
"lang": "es",
"value": "Un control de acceso roto para la creación de usuarios en Pydio Cells versión 2.2.9, permite a usuarios anónimos remotos crear usuarios estándar por medio del parámetro profile. (Además, a estos usuarios se les puede conceder varios permisos de administrador por medio del parámetro Roles)"
}
],
"lastModified": "2026-06-17T04:08:20.587",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pydio:cells:2.2.9:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "944EE3E1-C64D-4C91-BE35-46E8D82F4D0E"
},
{
"criteria": "cpe:2.3:a:pydio:cells:2.2.9:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "09769712-BFE4-4A43-9DAB-0517CF86F941"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}