Vulnerabilities > CVE-2019-15033 - Server-Side Request Forgery (SSRF) vulnerability in Pydio 6.0.8

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
pydio
CWE-918

Summary

Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.

Vulnerable Configurations

Part Description Count
Application
Pydio
1

Common Weakness Enumeration (CWE)