Junglewise Threat Intelligence

CVE-2023-49438: PYSEC-2023-248 - An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious

CVE-2023-49438 · Severity: low · CVSS 3.1 · Published 2023-12-26

Technologies: Flask-Security-Too (PyPI). Vendors: PyPI.

Executive brief

An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.

Affected products

  • PyPI Flask-Security-Too

Related threats