Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Open Redirect
Vulnerability Description
This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False. **Note:** Flask-Security is not maintained anymore.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Flask-Security 输入验证错误漏洞
Vulnerability Description
Flask-Security是一个应用软件。快速向Flask应用程序添加安全功能。 Flask-Security 存在输入验证错误漏洞,该漏洞源于对用户提供的数据处理不当,从而允许远程攻击者将受害者重定向到任意URL。
CVSS Information
N/A
Vulnerability Type
N/A