QID 996778
Date Published: 2024-01-23
QID 996778: Python (Pip) Security Update for pyload-ng (GHSA-pgpj-v85q-h5fm)
The pyload API allows any API call to be made using GET requests. Since the session cookie is not set to SameSite: strict, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. This proof of concept shows how an unauthenticated user could trick the administrator's browser into creating a new admin user.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-pgpj-v85q-h5fm for updates and patch information.
Vendor References
- GHSA-pgpj-v85q-h5fm -
github.com/advisories/GHSA-pgpj-v85q-h5fm
CVEs related to QID 996778
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pgpj-v85q-h5fm | pyload-ng |
|