Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| web2py(PyPI) | 0 | 2.14.6 | N/A |
CVSS Metrics