Lucene search

K
nvd[email protected]NVD:CVE-2023-22432
HistoryMar 06, 2023 - 12:15 a.m.

CVE-2023-22432

2023-03-0600:15:10
CWE-601
web.nvd.nist.gov
2
cve-2023-22432
web2py
open redirect
phishing attack

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

66.2%

Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

Affected configurations

Nvd
Node
web2pyweb2pyRange<2.23.1
VendorProductVersionCPE
web2pyweb2py*cpe:2.3:a:web2py:web2py:*:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

66.2%