CVE-2023-22432: Medium severity web2py vulnerability
Published Mar 5, 2023
·Updated
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
Affected Software
2 affected componentsFixes available
Web2py Web2py<2.23.1
pip/web2py<2.23.1
2.23.1
Event History
Mar 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Mar 6, 2023
Advisory Published
via GitHub·12:30 AM
Frequently Asked Questions
1
What is CVE-2023-22432?
CVE-2023-22432 is an open redirect vulnerability that exists in web2py versions prior to 2.23.1.
2
How does CVE-2023-22432 affect web2py?
CVE-2023-22432 allows a web2py user to be redirected to an arbitrary website by accessing a specially crafted URL, making them vulnerable to phishing attacks.
3
What is the severity level of CVE-2023-22432?
CVE-2023-22432 has a severity level of medium, with a CVSS score of 6.1.
4
Which version of web2py is affected by CVE-2023-22432?
Versions of web2py prior to 2.23.1 are affected by CVE-2023-22432.
5
How can I fix the CVE-2023-22432 vulnerability in web2py?
To fix the CVE-2023-22432 vulnerability in web2py, update to version 2.23.1 or later.