Incomplete Cleanup of User Data Allows Data Restoration by New User

Incomplete Cleanup of User Data Allows Data Restoration by New User

CVE-2019-12902 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.

Learn more about our User Device Pen Test.