CVE-2024-41810

MEDIUM NUCLEI

Twisted < 24.3.0 - Basic XSS

Title source: rule

Description

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.

Nuclei Templates (1)

Twisted - Open Redirect & XSS
MEDIUMby KoYejune0302,cheoljun99,sim4110,gy741
Shodan: html:'Twisted' html:"python"
FOFA: body="twisted" && "python"

Scores

CVSS v3 6.1
EPSS 0.6784
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
pypi/twisted 0 - 24.7.0rc1PyPI
twisted/twisted < 24.3.0
Published Jul 29, 2024
Tracked Since Feb 18, 2026