MEDIUM4.8
PYSEC-2026-1063
Web2py Reflected XSS vulnerability
Details
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/web2py
Introduced in:
0No fixed version published yet for web2py (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-4807[ADVISORY]
- https://github.com/web2py/web2py[PACKAGE]
- https://www.exploit-db.com/exploits/39821[WEB]
- http://packetstormsecurity.com/files/137070/Web2py-2.14.5-CSRF-XSS-Local-File-Inclusion.html[WEB]
- https://pypi.org/project/web2py[PACKAGE]
- https://github.com/advisories/GHSA-pvcp-73cg-6f77[ADVISORY]