CVE-2015-3431

critical
Published 2017-09-19 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://pydio.com/en/community/releases/pydio-core/pydio-607-security-release

Application impact

VendorProductVersionsFixed
pydiopydio{"endIncluding":"6.0.6"}

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.