References https://nvd.nist.gov/vuln/detail/CVE-2024-21644 https://github.com/pyload/pyload/security/advisories/GHSA-mqpq-2p68-46fv https://lmboke.com/archives/pyloadwei-shou-quan-fang-wen-lou-dong-cve-2024-21644 https://cn-sec.com/archives/2530111.html https://www.cvedetails.com/cve/CVE-2024-21644/ https://github.com/runZeroInc/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21644.yaml https://pentest-tools.com/vulnerabilities-exploits/pyload-flask-config-access-control_22487 https://www.ameeba.com/blog/cve-2024-21644-unauthenticated-exposure-of-flask-config-in-pyload/ https://baishya.xyz/posts/pyload-cves/ https://advisories.gitlab.com/pypi/pyload-ng/CVE-2024-21644/
Related VulnerabilitiesPyLoad /login 默认口令漏洞pyload /flash/addcrypted2 代码执行漏洞(CVE-2024-28397)pyLoad 远程命令执行漏洞PoCCVE-2023-0297: PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)PoCCVE-2024-21644: pyLoad Flask Config - Access ControlPoCCVE-2024-21645: pyload - Log InjectionPoCCVE-2024-28397: pyload-ng js2py - Remote Code ExecutionPoCCVE-2023-0297: pyLoad未授权远程代码执行漏洞CVE-2023-0297/CNNVD-202301-1121PoCpyload-default-login: PyLoad Default LoginpyLoad 操作系统命令注入漏洞Pyload CVE-2024-21645 日志注入漏洞pyLoad CVE-2024-21644 信息泄露漏洞