Junglewise Threat Intelligence

CVE-2024-22416: pyLoad pyload-ng CSRF leading to admin privilege escalation

CVE-2024-22416 · Severity: critical · CVSS 9.6 · Published 2024-01-19

Technologies: pyload-ng (PyPI), pyLoad Next Generation. Vendors: PyPI, pyLoad.

Executive brief

pyLoad is a download manager that provides an API for remote management. A security flaw allows attackers to perform unauthorized actions by tricking a logged-in administrator into visiting a malicious website. This could allow an attacker to create a new administrator account, effectively taking full control of the application and its data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in pyLoad due to the API's acceptance of GET requests for state-changing operations and the absence of 'SameSite: Strict' or 'SameSite: Lax' attributes on session cookies. An attacker can craft a malicious webpage that triggers an API call (e.g., /api/add_user) when visited by an authenticated administrator. Because the browser automatically includes the session cookie in the cross-site request, the API executes the command with the administrator's privileges. This can lead to full administrative takeover. The issue is fixed in version 0.5.0b3.dev78.

Affected products

  • pyLoad pyload-ng < 0.5.0b3.dev78

Timeline

  • 2024-01-17: disclosed
  • 2024-01-18: other: NVD published
  • 2024-01-19: advisory: GitHub Advisory published

References

Related threats