Showing 1 vulnerability on this page for flask-security

Signals CISA KEV Ransomware Nuclei
Flask-Middleware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Open Redirect Vulnerability

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-Security-Too allow redirects after many successful views (e.g. /login) by honoring the ?next query param. There is code in FS to validate that the url specified in the next parameter is either relative OR has the same netloc (network location) as the requesting

CWE-601May 17, 20211 related artifact
CVSS-v4.0EPSS3.29%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX