CVE-2024-1240
6.1
MEDIUM
CVSS 3.1
EPSS 0.32%
描述
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.
如何修補 CVE-2024-1240
要修補 CVE-2024-1240,請將受影響套件升級到下列已修補版本。
- —升級至 fe94451dcc2be90b3889e2fd9d07b483c8a6dccd 或更新版本
CVE-2024-1240 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < fe94451dcc2be90b3889e2fd9d07b483c8a6dccd | from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |