Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-22432
HistoryMar 06, 2023 - 12:00 a.m.

CVE-2023-22432

2023-03-0600:00:00
ubuntu.com
ubuntu.com
12
cve-2023-22432
web2py
open redirect
phishing attack
unix

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

66.2%

Open redirect vulnerability exists in web2py versions prior to 2.23.1. When
using the tool, a web2py user may be redirected to an arbitrary website by
accessing a specially crafted URL. As a result, the user may become a
victim of a phishing attack.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchweb2py< anyUNKNOWN

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.003

Percentile

66.2%