CVE-2019-15033: Pydio
High severity, CVSS 7.7. EPSS: 1.3% chance of exploitation in the next 30 days.
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.
Affected products
- Pydio Pydio: version 6.0.8 only
Published 2019-09-19. Last modified 2026-06-17.