NA

CVE-2023-22432

Published: 06/03/2023 Updated: 13/03/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Open redirect vulnerability exists in web2py versions before 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

web2py web2py

Github Repositories

TAKUTO YOSHIKAI Web Developer, Security Researcher, Bug Hunter Personal Works HONJA (Repository) | COWAKÉ Reported CVE CVE-2022-34265 (Django SQL Injection) | CVE-2023-22432 (web2py Open Redirect)

PoC for CVE-2023-22432 (web2py)

CVE-2023-22432 PoC verification of web2py vulnerability (CVE-2023-22432) A vulnerability (CVE-2023-22432) in web2py was disclosed on Jan 31, 2023 (US time) This article describes our discussion of this vulnerability and the results of our verification Vulnerability Summary This vulnerability is an open redirect vulnerability in web2py that allows an arbitrary URL to be specif