PT-2024-17577 · Pyload · Pyload

Gammac0De

·

Published

2024-11-15

·

Updated

2024-11-19

·

CVE-2024-1240

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pyload/pyload version 0.5.0
Description An open redirection vulnerability exists due to improper handling of the next parameter in the login functionality. This allows an attacker to redirect users to malicious sites, potentially leading to phishing or other malicious activities.
Recommendations For pyload/pyload version 0.5.0, update to pyload-ng 0.5.0b3.dev79 to resolve the issue. As a temporary workaround, consider restricting the use of the next parameter in the login functionality to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-1240
PYSEC-2024-123

Affected Products

Pyload