PT-2024-29577 · Twisted+5 · Twisted+5

V1Ktor0T

·

Published

2024-07-29

·

Updated

2025-12-26

·

CVE-2024-41810

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Twisted versions prior to 24.7.0rc1
Description The twisted.web.util.redirectTo function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL, this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. The function reflects the destination URL in the HTML body without any output encoding, allowing an attacker to inject arbitrary HTML into the response's body, ultimately leading to an XSS attack. This issue can be exploited in Firefox, allowing malicious JavaScript to run in the context of the victim's session, leading to unauthorized access or modification of the victim's account and information.
Recommendations For Twisted versions prior to 24.7.0rc1, update to version 24.7.0rc1 or later to fix the vulnerability. As a temporary workaround, consider restricting the use of the redirectTo function to minimize the risk of exploitation. Avoid using the redirectTo function with untrusted or user-controlled URLs until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-47073
AZL-47195
BDU:2025-04172
CVE-2024-41810
DLA-3970-1
DSA-5797-1
GHSA-CF56-G6W6-PQQ2
MGASA-2025-0054
OESA-2024-1983
OESA-2024-1984
OESA-2024-1985
OESA-2024-1986
OESA-2024-2052
OPENSUSE-SU-2024:14236-1
PYSEC-2024-75
RHSA-2024:7312
SUSE-SU-2024:2732-1
SUSE-SU-2024:2757-1
SUSE-SU-2024:2860-1
SUSE-SU-2024:2880-1
USN-6988-1

Affected Products

Astra Linux
Linuxmint
Red Os
Suse
Twisted
Ubuntu