add_package of the file src/pyload/core/api/init.py. Such manipulation leads to path traversal.This vulnerability is referenced as CVE-2023-47890. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.
SOCIAL SHARE CARD GENERATOR