CVE-2024-41810 is an HTML injection vulnerability in the twisted.web.util.redirectTo function of the Twisted framework, affecting versions prior to 24.7.0rc1. This flaw can lead to Reflected Cross-Site Scripting (XSS) if an attacker can control the redirect URL. Rated as Medium severity (CVSS 6.1), it requires user interaction and has a high FAUCET Risk Score of 98/100, indicating significant potential impact. While not actively exploited in the wild and lacking Metasploit or ExploitDB entries, Nuclei templates for detection exist, and there is currently no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 24.3.0CPE matchmatch criteria | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-41810
Sep 10, 2024Twisted vulnerable to HTML injection in HTTP redirect body
Jul 29, 2024python-twisted: Reflected XSS via HTML Injection in Redirect Response
Jul 29, 2024HTML injection in HTTP redirect body
Jul 9, 2024