flask-security是一个应用软件。快速向Flask应用程序添加安全功能。 Flask-Security-Too 存在输入验证错误漏洞,攻击者可以使用合法站点将此类链接发送给不知情的用户,然后将其重定向到他们想要的任何站点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Flask-Middleware | flask-security | <= 4.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Python Flask-Security contains an open redirect vulnerability. Existing code validates that the URL specified in the next parameter is either relative or has the same network location as the requesting URL. Certain browsers accept and fill in the blanks of possibly incomplete or malformed URLs. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-32618.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet