CVE-2024-24808

MEDIUM

pyLoad - Open Redirect

Title source: llm
STIX 2.1

Description

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the `get_redirect_url` function when redirecting users at login. This vulnerability has been patched with commit fe94451.

Scores

CVSS v3 4.7
EPSS 0.0236
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
pyload/pyload < 0.5.0
pypi/pyload-ng 0 - 0.5.0b3.dev79PyPI
Published Feb 06, 2024
Tracked Since Feb 18, 2026