CVE-2019-15033: SSRF
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15033?
CVE-2019-15033 is a vulnerability in Pydio 6.0.8 which allows an authenticated user to perform server-side request forgery (SSRF) during a Remote Link Feature download.
How can an attacker exploit CVE-2019-15033?
An attacker can specify an intranet address in the file parameter to index.php and send a file to a remote server, allowing them to perform SSRF.
What is the severity of CVE-2019-15033?
The severity of CVE-2019-15033 is high, with a CVSS score of 7.7.
What software versions are affected by CVE-2019-15033?
Only Pydio version 6.0.8 is affected by CVE-2019-15033.
How can I fix CVE-2019-15033?
Upgrade Pydio to a version that is not affected by this vulnerability.