Executive brief
pyLoad is a download manager that provides an API for remote management. A security flaw allows attackers to perform unauthorized actions by tricking a logged-in administrator into visiting a malicious website. This could allow an attacker to create a new administrator account, effectively taking full control of the application and its data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in pyLoad due to the API's acceptance of GET requests for state-changing operations and the absence of 'SameSite: Strict' or 'SameSite: Lax' attributes on session cookies. An attacker can craft a malicious webpage that triggers an API call (e.g., /api/add_user) when visited by an authenticated administrator. Because the browser automatically includes the session cookie in the cross-site request, the API executes the command with the administrator's privileges. This can lead to full administrative takeover. The issue is fixed in version 0.5.0b3.dev78.
Affected products
- pyLoad pyload-ng < 0.5.0b3.dev78
Timeline
- 2024-01-17: disclosed
- 2024-01-18: other: NVD published
- 2024-01-19: advisory: GitHub Advisory published