Vulnerabilities (CVE)

Filtered by vendor Pyload Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47890 1 Pyload 1 Pyload 2024-01-11 N/A 8.8 HIGH
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
CVE-2024-21644 1 Pyload 1 Pyload 2024-01-11 N/A 7.5 HIGH
pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.
CVE-2024-21645 1 Pyload 1 Pyload 2024-01-11 N/A 5.3 MEDIUM
pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by `pyload`. Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act. This vulnerability has been patched in version 0.5.0b3.dev77.