VYPR
Critical severity9.8OSV Advisory· Published Jan 15, 2019· Updated Jun 17, 2026

CVE-2018-20718

CVE-2018-20718

Description

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: 6.2rc, ajaxplorer-core-4.3.1, ajaxplorer-core-4.3.2, …
  • Pydio/Pydio2 versions
    cpe:2.3:a:pydio:pydio:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pydio:pydio:*:*:*:*:*:*:*:*range: <8.2.2
    • (no CPE)range: <8.2.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.