References https://nvd.nist.gov/vuln/detail/CVE-2024-21644 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21644.yaml https://pentest-tools.com/vulnerabilities-exploits/pyload-flask-config-access-control_22487 https://advisories.gitlab.com/pkg/pypi/pyload-ng/ https://www.ameeba.com/blog/cve-2024-21644-unauthenticated-exposure-of-flask-config-in-pyload/ https://vulners.com/cve/CVE-2024-21644 https://www.ddpoc.com/DVB-2024-6161.html https://stack.chaitin.com/vuldb/detail/80161369-e501-44f5-8a62-31461bda7385 https://cn-sec.com/archives/2530111.html https://cn-sec.com/archives/2533135.html https://www.youtube.com/watch?v=C6I8Jxxjik0 https://baishya.xyz/posts/pyload-cves/ https://www.scribd.com/document/785098408/CVE-2024-21644 https://feedly.com/cve/vendors/pyload https://zhuanlan.zhihu.com/p/1932214870562047555 https://www.ctfiot.com/blog/page/596 https://blog.csdn.net/2401_82670286/article/details/135914798 https://zhuanlan.zhihu.com/p/4249525215
Related VulnerabilitiesPyLoad /login 默认口令漏洞pyload /flash/addcrypted2 代码执行漏洞(CVE-2024-28397)pyLoad 远程命令执行漏洞PoCCVE-2023-0297: PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)PoCCVE-2024-21644: pyLoad Flask Config - Access ControlPoCCVE-2024-21645: pyload - Log InjectionPoCCVE-2024-28397: pyload-ng js2py - Remote Code ExecutionPoCCVE-2023-0297: pyLoad未授权远程代码执行漏洞CVE-2023-0297/CNNVD-202301-1121PoCpyload-default-login: PyLoad Default LoginpyLoad /render/info.html 未授权访问漏洞(CVE-2024-21644)pyLoad 操作系统命令注入漏洞