cve/2024/CVE-2024-21644.md
2024-06-09 00:33:16 +00:00

996 B

CVE-2024-21644

Description

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the SECRET_KEY variable. This issue has been patched in version 0.5.0b3.dev77.

POC

Reference

Github