CVE-2022-33146: Medium severity web2py vulnerability
Published Jun 27, 2022
·Updated
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
Affected Software
1 affected component
Web2py Web2py<2.22.5
Remediation
Event History
Jun 27, 2022
CVE Published
via MITRE·12:20 AM
Data Sourced
via MITRE·12:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-33146?
CVE-2022-33146 is an open redirect vulnerability in web2py versions prior to 2.22.5.
2
How does CVE-2022-33146 work?
CVE-2022-33146 allows a remote attacker to redirect a user to an arbitrary website and conduct a phishing attack by having the user access a specially crafted URL.
3
What is the severity of CVE-2022-33146?
CVE-2022-33146 has a severity rating of 6.1 (medium).
4
What software versions are affected by CVE-2022-33146?
web2py versions prior to 2.22.5 are affected by CVE-2022-33146.
5
How can I fix CVE-2022-33146?
To fix CVE-2022-33146, update to web2py version 2.22.5 or later.