PT-2026-27492 · Pyload · Pyload
Yueyuel
·
Publicado
2026-03-24
·
Atualizado
2026-03-25
·
CVE-2026-33511
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pyLoad versions 0.4.20 through 0.5.0b3.dev96
Description
pyLoad, a download manager written in Python, contains a flaw in its ClickNLoad feature. The
local check decorator can be circumvented through HTTP Host header spoofing. This allows unauthenticated remote attackers to access endpoints restricted to localhost. Successful exploitation enables attackers to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code.Recommendations
Update to version 0.5.0b3.dev97 or later.
Exploit
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pyload