返回列表

CVE-2024-21644: pyLoad Flask Config - Access Control

PoC
2025-08-01

影响软件

pyLoad Flask Config

关联产品

漏洞描述

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

PoC / 利用代码

登录后可查看 PoC 内容

查看原文