We found results for “”
CVE-2024-22416
Good to know:
Date: January 17, 2024
pyLoad is a free and open-source Download Manager written in pure Python. The "pyload" API allows any API call to be made using GET requests. Since the session cookie is not set to "SameSite: strict", this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result any API call can be made via a CSRF attack by an unauthenticated user. This issue has been addressed in release "0.5.0b3.dev78". All users are advised to upgrade.
Language: Python
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
CWE-352Top Fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


