An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-12-26T00:00:00
Updated: 2024-08-02T21:53:45.372Z
Reserved: 2023-11-27T00:00:00
Link: CVE-2023-49438
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-26T22:15:13.973
Modified: 2024-01-14T02:15:46.610
Link: CVE-2023-49438
Redhat
No data.