7.5

CVE-2023-0434

Exploit

Improper Input Validation in pyload/pyload

Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PyloadPyload Version <= 0.4.9
PyloadPyload Version0.5.0 Updatebeta1
PyloadPyload Version0.5.0 Updatebeta2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.82% 0.523
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@huntr.dev 5.4 0.2 5.2
CVSS:3.0/AV:P/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/pyload/pyload/commit/a2b1eb1028f45ac58dea5f58593c1d3db2b4a104
Patch
Third Party Advisory
https://huntr.dev/bounties/7d9332d8-6997-483b-9fb9-bcf2ae01dad4
Patch
Third Party Advisory
Exploit