CVE-2026-25198
Unknown
Unknown - Not Provided
Open Redirect Vulnerability in web2py Enables Phishing Attacks
Publication date: 2026-02-05
Last updated on: 2026-02-05
Assigner: JPCERT/CC
Description
Description
web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website when accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| web2py | web2py | to 2.27.1-stable+timestamp.2023.11.16.08.03.57 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-601 | The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. |