{"api_version":"1","generated_at":"2026-07-23T07:16:08+00:00","cve":"CVE-2018-14772","urls":{"html":"https://cve.report/CVE-2018-14772","api":"https://cve.report/api/cve/CVE-2018-14772.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-14772","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-14772"},"summary":{"title":"CVE-2018-14772","description":"Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-10-16 22:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"http://coastalsec.io/cve-2018-14772-remote-code-execution","name":"http://coastalsec.io/cve-2018-14772-remote-code-execution","refsource":"MISC","tags":["Patch","Technical Description","Third Party Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-14772","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14772","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"14772","vulnerable":"1","versionEndIncluding":"8.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pydio","cpe5":"pydio","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-14772","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://coastalsec.io/cve-2018-14772-remote-code-execution","refsource":"MISC","url":"http://coastalsec.io/cve-2018-14772-remote-code-execution"}]}},"nvd":{"publishedDate":"2018-10-16 22:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pydio:pydio:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2.1","versionEndIncluding":"8.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"14772","Ordinal":"131480","Title":"CVE-2018-14772","CVE":"CVE-2018-14772","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"14772","Ordinal":"1","NoteData":"Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"14772","Ordinal":"2","NoteData":"2018-10-16","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"14772","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}