Vendor
high
advisory
pyLoad Session Invalidation Failure After Privilege Revocation
1 TTPAn improper implementation of the set_user_permission API endpoint in pyLoad allows users to retain elevated permissions for up to 31 days after an administrator has explicitly revoked their access.
pyLoad
privilege-escalation
persistence
api-security
1t
high
advisory
Authentication Bypass and Brute-Force Oracle in pyload-ng
2 TTPsAn insecure permission check in the pyload-ng API allows any authenticated user to perform administrative password brute-forcing via a side-channel oracle.
pyload-ng +1
credential-access
authentication-bypass
web-application
2t