VDB
Sign up
MEDIUM6.1

PYSEC-2024-123

Quick fix

PYSEC-2024-123 — pyload-ng: upgrade to the fixed version with the command below.

pip install --upgrade 'pyload-ng>=fe94451dcc2be90b3889e2fd9d07b483c8a6dccd'

Details

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyload-ng
Introduced in: 0Fixed in: fe94451dcc2be90b3889e2fd9d07b483c8a6dccd
Fixpip install --upgrade 'pyload-ng>=fe94451dcc2be90b3889e2fd9d07b483c8a6dccd'

References