Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| web2py(PyPI) | 0 | 2.22.5 | N/A |
CVSS Metrics