CVE-2023-32750

CVE-2023-32750

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

Source: CVE-2023-32750

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다