First published: Thu Sep 19 2019(Updated: )
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pydio Cells | =6.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15033 is a vulnerability in Pydio 6.0.8 which allows an authenticated user to perform server-side request forgery (SSRF) during a Remote Link Feature download.
An attacker can specify an intranet address in the file parameter to index.php and send a file to a remote server, allowing them to perform SSRF.
The severity of CVE-2019-15033 is high, with a CVSS score of 7.7.
Only Pydio version 6.0.8 is affected by CVE-2019-15033.
Upgrade Pydio to a version that is not affected by this vulnerability.