Vulnerability Details CVE-2024-41810
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.242
EPSS Ranking 95.8%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-41810
-
cpe:2.3:a:twisted:twisted:-
-
cpe:2.3:a:twisted:twisted:10.0.0
-
cpe:2.3:a:twisted:twisted:10.1.0
-
cpe:2.3:a:twisted:twisted:10.2.0
-
cpe:2.3:a:twisted:twisted:11.0.0
-
cpe:2.3:a:twisted:twisted:11.1.0
-
cpe:2.3:a:twisted:twisted:12.0.0
-
cpe:2.3:a:twisted:twisted:12.1.0
-
cpe:2.3:a:twisted:twisted:12.2.0
-
cpe:2.3:a:twisted:twisted:12.3.0
-
cpe:2.3:a:twisted:twisted:13.0.0
-
cpe:2.3:a:twisted:twisted:13.1.0
-
cpe:2.3:a:twisted:twisted:13.2.0
-
cpe:2.3:a:twisted:twisted:14.0.0
-
cpe:2.3:a:twisted:twisted:14.0.1
-
cpe:2.3:a:twisted:twisted:14.0.2
-
cpe:2.3:a:twisted:twisted:15.0.0
-
cpe:2.3:a:twisted:twisted:15.1.0
-
cpe:2.3:a:twisted:twisted:15.2.0
-
cpe:2.3:a:twisted:twisted:15.2.1
-
cpe:2.3:a:twisted:twisted:15.3.0
-
cpe:2.3:a:twisted:twisted:15.4.0
-
cpe:2.3:a:twisted:twisted:15.5.0
-
cpe:2.3:a:twisted:twisted:16.0.0
-
cpe:2.3:a:twisted:twisted:16.1.0
-
cpe:2.3:a:twisted:twisted:16.1.1
-
cpe:2.3:a:twisted:twisted:16.2.0
-
cpe:2.3:a:twisted:twisted:16.3.0
-
cpe:2.3:a:twisted:twisted:16.3.1
-
cpe:2.3:a:twisted:twisted:16.3.2
-
cpe:2.3:a:twisted:twisted:16.4.0
-
cpe:2.3:a:twisted:twisted:16.4.1
-
cpe:2.3:a:twisted:twisted:16.5.0
-
cpe:2.3:a:twisted:twisted:16.6.0
-
cpe:2.3:a:twisted:twisted:17.1.0
-
cpe:2.3:a:twisted:twisted:17.5.0
-
cpe:2.3:a:twisted:twisted:17.9.0
-
cpe:2.3:a:twisted:twisted:18.4.0
-
cpe:2.3:a:twisted:twisted:18.7.0
-
cpe:2.3:a:twisted:twisted:18.9.0
-
cpe:2.3:a:twisted:twisted:19.10.0
-
cpe:2.3:a:twisted:twisted:19.2.0
-
cpe:2.3:a:twisted:twisted:19.2.1
-
cpe:2.3:a:twisted:twisted:19.7.0
-
cpe:2.3:a:twisted:twisted:20.11.0
-
cpe:2.3:a:twisted:twisted:20.3.0
-
cpe:2.3:a:twisted:twisted:21.2.0
-
cpe:2.3:a:twisted:twisted:21.7.0
-
cpe:2.3:a:twisted:twisted:22.1.0
-
cpe:2.3:a:twisted:twisted:22.10.0
-
cpe:2.3:a:twisted:twisted:22.2.0
-
cpe:2.3:a:twisted:twisted:22.4.0
-
cpe:2.3:a:twisted:twisted:22.8.0
-
cpe:2.3:a:twisted:twisted:23.10.0
-
cpe:2.3:a:twisted:twisted:23.8.0
-
cpe:2.3:a:twisted:twisted:24.2.0
-
cpe:2.3:a:twisted:twisted:24.3.0
-
cpe:2.3:a:twisted:twisted:8.0.0
-
cpe:2.3:a:twisted:twisted:8.0.1
-
cpe:2.3:a:twisted:twisted:8.1.0
-
cpe:2.3:a:twisted:twisted:8.2.0
-
cpe:2.3:a:twisted:twisted:9.0.0