pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| pyload-ng(PyPI) | 0 | 0.5.0b3.dev77 | N/A |
CVSS Metrics