Vulnerabilities > Pydio > Pydio > 7.0.3

DATE CVE VULNERABILITY TITLE RISK
2018-07-23 CVE-2018-1999017 Server-Side Request Forgery (SSRF) vulnerability in Pydio
Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivoting requests through the server.
network
low complexity
pydio CWE-918
4.0
2018-07-23 CVE-2018-1999016 Cross-site Scripting vulnerability in Pydio
Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline.php line 48; ./core/vendor/dapphp/securimage/examples/test.mysql.static.php lines: 114,118 that can result in an unauthenticated remote attacker manipulating the web client via XSS code injection.
network
pydio CWE-79
4.3