Authenticated SSRF Vulnerability in Pydio by Pydio
CVE-2019-15033
7.7HIGH
What is CVE-2019-15033?
The Authenticated SSRF vulnerability in Pydio 6.0.8 allows attackers to leverage the Remote Link Feature to download files from arbitrary intranet addresses. By manipulating the 'file' parameter in the index.php, an attacker can redirect requests to internal servers, potentially exposing sensitive data or compromising internal services. This highlights the need for stringent validation of user inputs and reinforces the importance of protecting internal network resources.
