An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| Flask-Security-Too(PyPI) | 0 | 5.3.3 | N/A |
CVSS Metrics