pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the SECRET_KEY variable. This issue has been patched in version 0.5.0b3.dev77.
| Software | From | Fixed in |
|---|---|---|
pyload-ng
|
- | 0.5.0b3.dev77 |
| pyload / pyload | - | 0.4.9.x |
| pyload / pyload | 0.5.0-beta1 | 0.5.0-beta1.x |
| pyload / pyload | 0.5.0-beta2 | 0.5.0-beta2.x |