Logo
componentpython3-flask-user
Name
python3-flask-user
Version
0.6.19
Type
library
Description
Customizable user account management for Flask
Licenses
BSD-2-Clause
PURL
-
CPE
cpe:2.3:*:*:flask-user:0.6.19:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
0.6.19
scarthgap
0.6.19

Vulnerabilities#


Name
Analysis
Description
Exploitable
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.