Vulnerability Details CVE-2024-32880
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 87.8%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2024-32880
-
cpe:2.3:a:pyload:pyload:-
-
cpe:2.3:a:pyload:pyload:0.1
-
cpe:2.3:a:pyload:pyload:0.1.1
-
cpe:2.3:a:pyload:pyload:0.2
-
cpe:2.3:a:pyload:pyload:0.2.1
-
cpe:2.3:a:pyload:pyload:0.2.2
-
cpe:2.3:a:pyload:pyload:0.3
-
cpe:2.3:a:pyload:pyload:0.3.1
-
cpe:2.3:a:pyload:pyload:0.3.2
-
cpe:2.3:a:pyload:pyload:0.4
-
cpe:2.3:a:pyload:pyload:0.4.1
-
cpe:2.3:a:pyload:pyload:0.4.2
-
cpe:2.3:a:pyload:pyload:0.4.20
-
cpe:2.3:a:pyload:pyload:0.4.3
-
cpe:2.3:a:pyload:pyload:0.4.4
-
cpe:2.3:a:pyload:pyload:0.4.5
-
cpe:2.3:a:pyload:pyload:0.4.6
-
cpe:2.3:a:pyload:pyload:0.4.7
-
cpe:2.3:a:pyload:pyload:0.4.8
-
cpe:2.3:a:pyload:pyload:0.4.9
-
cpe:2.3:a:pyload:pyload:0.5.0