CVE-2015-6961: Medium severity web2py vulnerability
Published Oct 18, 2017
·Updated
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to user/logout.
Affected Software
1 affected component
Web2py Web2py=2.9.11
Remediation
Event History
Oct 18, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6961?
CVE-2015-6961 is classified as a medium severity vulnerability due to its potential for phishing attacks.
2
How do I fix CVE-2015-6961?
To fix CVE-2015-6961, update Web2py to version 2.9.12 or later.
3
What type of vulnerability is CVE-2015-6961?
CVE-2015-6961 is an open redirect vulnerability that can lead to unauthorized URL redirection.
4
What software is affected by CVE-2015-6961?
CVE-2015-6961 affects Web2py version 2.9.11.
5
How can CVE-2015-6961 be exploited?
CVE-2015-6961 can be exploited by using a crafted URL in the _next parameter of the logout function to redirect users to malicious sites.