CVE-2023-22432
CVSS V2 None
CVSS V3 None
Description
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
Overview
- CVE ID
- CVE-2023-22432
- Assigner
- vultures@jpcert.or.jp
- Vulnerability Status
- Analyzed
- Published Version
- 2023-03-06T00:15:10
- Last Modified Date
- 2023-03-13T17:41:51
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:web2py:web2py:*:*:*:*:*:*:*:* | 1 | OR | 2.23.1 |
References
Reference URL | Reference Tags |
---|---|
http://web2py.com/ | Product |
http://web2py.com/init/default/download | Product |
https://jvn.jp/en/jp/JVN78253670/ | Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-22432 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22432 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 05:57:23 | Added to TrackCVE | |||
2023-04-17 05:57:25 | Weakness Enumeration | new |