PT-2024-21799 · Unknown · Docassemble

Richighimi

·

Published

2024-02-29

·

Updated

2025-09-02

·

CVE-2024-27291

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Docassemble versions prior to 1.4.97
Description The issue allows an attacker to create a URL that acts as an open redirect. This can potentially be used to redirect users to malicious websites.
Recommendations For versions prior to 1.4.97, update to version 1.4.97 or later to resolve the issue. As a temporary workaround, manually apply the changes of the patch and restart the server.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-27291
GHSA-7WXF-R2QV-9XWR

Affected Products

Docassemble