CVE-2024-1240: Open Redirection in pyload/pyload
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1240?
CVE-2024-1240 is classified as a medium severity vulnerability due to its potential for enabling redirection to malicious sites.
How do I fix CVE-2024-1240?
To fix CVE-2024-1240, update pyload to a version later than 0.5.0 where the issue has been resolved.
Who is affected by CVE-2024-1240?
Users of pyload version 0.5.0 are affected by CVE-2024-1240 due to improper handling of the 'next' parameter.
What type of vulnerability is CVE-2024-1240?
CVE-2024-1240 is an open redirection vulnerability that can lead to phishing attacks.
Can CVE-2024-1240 be exploited remotely?
Yes, CVE-2024-1240 can be exploited remotely by attackers to redirect users to harmful websites.