CVE-2024-22416 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability affecting pyLoad, an open-source download manager. The flaw allows unauthenticated attackers to execute arbitrary API calls via GET requests due to the absence of a SameSite: strict cookie policy. This vulnerability carries a CVSS score of 8.8 (High), indicating a critical risk with high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion, and users are strongly advised to upgrade to version 0.5.0b3.dev78 or later to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.0b3.dev78CPE matchmatch criteria | cpe:2.3:a:pyload-ng_project:pyload-ng:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.