CVE-2024-41810
MEDIUM NUCLEITwisted < 24.3.0 - Basic XSS
Title source: ruleDescription
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.
Nuclei Templates (1)
Twisted - Open Redirect & XSS
MEDIUMby KoYejune0302,cheoljun99,sim4110,gy741
Shodan:
html:'Twisted' html:"python"
FOFA:
body="twisted" && "python"
References (3)
Scores
CVSS v3
6.1
EPSS
0.6784
EPSS Percentile
98.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-80
CWE-79
Status
published
Products (2)
pypi/twisted
0 - 24.7.0rc1PyPI
twisted/twisted
< 24.3.0
Published
Jul 29, 2024
Tracked Since
Feb 18, 2026