CVE-2019-15032

Publication date

2019-09-19 16:03:06

Family

mitre

State

PUBLISHED

Description

Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.