CVE-2024-41810
MEDIUM NUCLEItwisted < 24.7.0rc1 - Reflected Cross-Site Scripting via redirectTo Function
Title source: llmExploitation Summary
CVE-2024-41810 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.
Nuclei Templates (1)
Twisted - Open Redirect & XSS
MEDIUMby KoYejune0302,cheoljun99,sim4110,gy741
Shodan:
html:'Twisted' html:"python"
FOFA:
body="twisted" && "python"
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/twisted/twisted/security/advisories/GHSA-cf56-g6w6-pqq2
Scores
CVSS v3
6.1
EPSS
0.0111
EPSS Percentile
61.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
CWE-79
Status
published
Products (2)
pypi/twisted
0 - 24.7.0rc1PyPI
twisted/twisted
< 24.3.0
Published
Jul 29, 2024
Tracked Since
Feb 18, 2026