Brandon T. Elliott

1 exploit Active since Dec 2023
CVE-2023-49438 NOMISEC MEDIUM WRITEUP
Flask-Security-Too <=5.3.2 - Open Redirect via Next Parameter
An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.
5 stars
CVSS 6.1