CVE-2023-32750 Information
Jun 09, 2023
cve
Description
Pydio Cells through 4.1.2 allows SSRF. For longer running processes Pydio Cells allows for the creation of jobs which are run in the background. The job emote-download\ can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.
Reference
https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analyses https://www.redteam-pentesting.de/advisories/rt-sa-2023-005/
Share on: