Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cgrj-xjm7-9q27

Опубликовано: 28 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Open redirect in web2py

Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

Пакеты

Наименование

web2py

pip
Затронутые версииВерсия исправления

< 2.22.5

2.22.5

EPSS

Процентиль: 69%
0.00598
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
nvd
больше 3 лет назад

Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
debian
больше 3 лет назад

Open redirect vulnerability in web2py versions prior to 2.22.5 allows ...

EPSS

Процентиль: 69%
0.00598
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601