CVE-2023-32750
MEDIUMPydio Cells < 3.0.12 - Server-Side Request Forgery via Remote Download Job
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-32750. PoCs published by RedTeam Pentesting GmbH.
AI-analyzed exploit summary This exploit demonstrates a Server-Side Request Forgery (SSRF) vulnerability in Pydio Cells 4.1.2 and earlier. It uses the 'remote-download' job to force the server to make arbitrary HTTP requests, potentially accessing internal services.
Description
Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.
Exploits (1)
This exploit demonstrates a Server-Side Request Forgery (SSRF) vulnerability in Pydio Cells 4.1.2 and earlier. It uses the 'remote-download' job to force the server to make arbitrary HTTP requests, potentially accessing internal services.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N