QID 150803
Date Published: 2024-02-16
QID 150803: pyLoad Improper Access Control Vulnerability (CVE-2024-21644)
pyLoad is a web-based download manager designed for downloading files from popular video-hosting sites, torrents, and file-hosting websites.
In any installed version of pyLoad, an unauthenticated user can navigate to a specific URL and potentially expose the Flask configuration, revealing sensitive information such as the `SECRET_KEY` variable.
Affected Versions:
pyLoad upto 0.4.9
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to "render/info.html" endpoint and based on the response confirms if the target is vulnerable.
Successful exploitation would lead to Information Disclosure vulnerability, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Customers are advised to upgrade to latest pyLoad to remediate this vulnerability. For more information related to this vulnerability please refer to pyLoad Advisory.
Vendor References
CVEs related to QID 150803
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| pyLoad |
|