CVE-2016-4808: WEB2PY
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
Affected products
- WEB2PY WEB2PY: up to and including 2.14.5
Published 2017-01-11. Last modified 2026-06-17.