VulnerabilityModified
CVE-2023-32750
Pydio Cells through 4.1.2 allows SSRF.
MEDIUM 6.5EPSS 3.85%
Does this matter?
Lower severity and a low EPSS score (3.85%). Track it; it rarely justifies an emergency change on its own.
Description
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.85% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- pydio/cells
- Source
- cve@mitre.org
References
- https://www.redteam-pentesting.de/advisories/rt-sa-2023-005/Exploit, Third Party Advisory
- https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analysesThird Party Advisory
- https://www.redteam-pentesting.de/advisories/rt-sa-2023-005/Exploit, Third Party Advisory
- https://www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analysesThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.