QID 150803

Date Published: 2024-02-16

QID 150803: pyLoad Improper Access Control Vulnerability (CVE-2024-21644)

pyLoad is a web-based download manager designed for downloading files from popular video-hosting sites, torrents, and file-hosting websites.

In any installed version of pyLoad, an unauthenticated user can navigate to a specific URL and potentially expose the Flask configuration, revealing sensitive information such as the `SECRET_KEY` variable.

Affected Versions:
pyLoad upto 0.4.9

QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to "render/info.html" endpoint and based on the response confirms if the target is vulnerable.

Successful exploitation would lead to Information Disclosure vulnerability, which can help the attacker carry out further attacks and obtain sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade to latest pyLoad to remediate this vulnerability. For more information related to this vulnerability please refer to pyLoad Advisory.

    CVEs related to QID 150803

    Software Advisories
    Advisory ID Software Component Link
    pyLoad URL Logo github.com/pyload/pyload/security/advisories/GHSA-mqpq-2p68-46fv