Description
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-5790 | Web2py Reflected XSS vulnerability |
Github GHSA |
GHSA-pvcp-73cg-6f77 | Web2py Reflected XSS vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:39:26.323Z
Reserved: 2016-05-15T00:00:00.000Z
Link: CVE-2016-4807
No data.
Status : Modified
Published: 2017-01-11T16:59:00.237
Modified: 2026-06-17T00:48:15.257
Link: CVE-2016-4807
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA