Skip to main content

Threats Tagged 'brew-scrapy-cve-2024-41810'

View all threats tagged with 'brew-scrapy-cve-2024-41810'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: brew-scrapy-cve-2024-41810

Threats Tagged 'brew-scrapy-cve-2024-41810'

Click on any threat for detailed analysis and mitigation recommendations

The Twisted web framework's redirectTo function contains an HTML injection vulnerability that can lead to reflected cross-site scripting (XSS) if an attacker controls the redirect URL. This occurs because the redirectTo function reflects the destination URL in the HTML body without encoding, allowing injection of arbitrary HTML/JavaScript. The vulnerability is exploitable only in Firefox due to its handling of the redirect response body. Exploitation could allow malicious scripts to run in the victim's session context, potentially leading to unauthorized access or actions. Affected versions are Twisted versions used by Scrapy from 2.9.0 up to but not including 2.11.2_3. A patch is available for this issue.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: brew-scrapy-cve-2024-41810
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses