CVE-2023-45158: WEB2PY
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
Affected products
- WEB2PY WEB2PY: up to and including 2.24.1
Published 2023-10-16. Last modified 2026-06-17.