NA

CVE-2023-32750

Published: 08/06/2023 Updated: 16/06/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Pydio Cells up to and including 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pydio cells

Exploits

Pydio Cells versions 412 and below suffer from a server-side request forgery vulnerability ...