CVE-2024-1240
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | pyload-ng | <fe94451dcc2be90b3889e2fd9d07b483c8a6dccd | fe94451dcc2be90b3889e2fd9d07b483c8a6dccd |
References
Verify integrity in audit chain (admin only). AS-IS.