pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Aug 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pyload
Pyload pyload |
|
Vendors & Products |
Pyload
Pyload pyload |
Mon, 11 Aug 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91. | |
Title | PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-11T22:21:52.225Z
Updated: 2025-08-12T15:49:56.057Z
Reserved: 2025-08-07T18:27:23.306Z
Link: CVE-2025-55156

Updated: 2025-08-12T15:49:51.562Z

Status : Awaiting Analysis
Published: 2025-08-11T23:15:26.850
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-55156

No data.