web2py@1.98.2 vulnerabilities
full-stack framework for rapid development and prototyping of secure database-driven web-based applications, written and programmable in Python.
-
latest version
2.1.1
-
first published
13 years ago
-
latest version published
12 years ago
-
licenses detected
- (BSD-2-Clause OR BSD-3-Clause)[0,)
Direct Vulnerabilities
Known vulnerabilities in the web2py package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Brute Force due to not properly checking if a host is denied before verifying passwords. How to fix Brute Force? A fix was pushed into the |
[0,)
|
Affected versions of this package are vulnerable to Arbitrary Code Execution via the hardcoded encryption key when calling the How to fix Arbitrary Code Execution? A fix was pushed into the |
[0,)
|
Affected versions of this package are vulnerable to Information Exposure. A remote attacker can obtain the How to fix Information Exposure? A fix was pushed into the |
[0,)
|
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) which allows an attacker to trick a logged-in administrator into performing unwanted actions. How to fix Cross-site Request Forgery (CSRF)? A fix was pushed into the |
[0,)
|
Affected versions of this package are vulnerable to Open Redirect when a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. How to fix Open Redirect? A fix was pushed into the |
[0,)
|
Affected versions of this package are vulnerable to Open Redirect which allows a remote attacker to redirect a user to an arbitrary website and conduct a phishing attack by having a user access a specially crafted How to fix Open Redirect? A fix was pushed into the |
[0,)
|
web2py is open source full-stack enterprise framework for agile development of secure database-driven web-based applications, written and programmable in Python. Affected versions of this package are vulnerable to Open Redirect in How to fix Open Redirect? Upgrade |
[,2.12.1)
|
web2py is an open source full-stack enterprise framework for agile development of secure database-driven web-based applications, written and programmable in Python. Affected versions of this package are vulnerable to Arbitrary Code Execution. The How to fix Arbitrary Code Execution? Upgrade |
[,2.14.2)
|
Cross-site Scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
[,2.3.2)
|