CVE-2023-22432Medium· 6.1▾ TwilightPoC availableOpen redirect in web2py
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.4%
2.4% → 2.4%
1 GitHub repo · Nuclei ×1
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
web2py < 2.23.1Upgrade to a patched release:
web2py 2.23.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-33146Medium· 6.1Open redirect in web2py
CVE-2016-4807Medium· 4.8Web2py Reflected XSS vulnerability
CVE-2016-4808Medium· 4.5Web2py Cross-Site Request Forgery vulnerability
CVE-2026-25198Medium· 4.7web2py has an Open Redirect Vulnerability
CVE-2016-3954Medium· 5.5web2py exposure of sensitive information