ZeroHour

CVE-2016-3957

PoC
CVSS 3.0
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.

Vendors
web2py
Products
web2py
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.