Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2024-22416— Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

CVSS 9.7 · Critical EPSS 5.90% · P91
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-22416

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Source: NVD (National Vulnerability Database)
Vulnerability Description
pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since the session cookie is not set to `SameSite: strict`, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result any API call can be made via a CSRF attack by an unauthenticated user. This issue has been addressed in release `0.5.0b3.dev78`. All users are advised to upgrade.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
跨站请求伪造(CSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
pyload 跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
pyload是一个用 Python 编写的免费开源下载管理器,设计为极其轻量级、易于扩展且可通过 Web 完全管理。 pyload 0.5.0b3.dev78之前版本存在跨站请求伪造漏洞,该漏洞源于存在跨站请求伪造(CSRF)漏洞,未经身份验证的用户可以使用GET请求进行任何API调用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
pyloadpyload < 0.5.0b3.dev78 -

II. Public POCs for CVE-2024-22416

#POC DescriptionSource LinkShenlong Link
1CVE-2024-22416 exploit experimentshttps://github.com/mindstorm38/ensimag-secu3a-cve-2024-22416POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-22416

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2024-22416

No comments yet


Leave a comment