CVE-2024-22416
Pyload-ng_project
CVE-2024-22416 in pyLoad allows unauthenticated attackers to perform actions via Cross-Site Request Forgery (CSRF). This vulnerability arises because the session cookie lacks SameSite: strict
protection, enabling malicious actors to execute arbitrary API calls. pyLoad, a Python-based download manager, is susceptible to CSRF attacks due to insufficient session cookie security. With an SVRS of 77, this vulnerability is nearing critical levels, indicating a high risk of exploitation, especially given the availability of active exploits. Successful exploitation could lead to unauthorized modifications, data theft, or complete system compromise by unauthenticated users. Immediate action, including upgrading to version 0.5.0b3.dev78, is strongly advised to mitigate the potential damage from this significant security flaw.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.