CVE-2024-21645 is a log injection vulnerability in pyLoad, an open-source Python download manager. This flaw allows unauthenticated attackers to inject arbitrary messages into pyLoad's logs. Rated as Medium severity (CVSS 5.3), the vulnerability has a low attack complexity and can be exploited remotely without user interaction, potentially enabling attackers to obscure their actions or frame others. While not actively exploited in the wild and lacking public exploit code on platforms like Metasploit or ExploitDB, a Nuclei template exists for detection, and its high EPSS score suggests a notable likelihood of future exploitation. The vulnerability has been patched in pyLoad version 0.5.0b3.dev77.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.4.9CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:* | ||
0.5.0CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:0.5.0:beta1:*:*:*:*:*:* | ||
0.5.0CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:0.5.0:beta2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.