mirror of
https://github.com/wassname/flask-security.git
synced 2026-06-29 16:30:04 +08:00
48dd3fa5bf5b1e53d8707e17bb95903d7a2f98b7
NextFormMixin was missing validations check on redirection [1]. Only internal redirections are now allowed. Attack Example: http://127.0.0.1:5000/login?next=http://google.com (it should not redirect to google.com) wq [1] https://www.owasp.org/index.php/Top_10_2010-A10-Unvalidated_Redirects_and_Forwards
Flask-Security ============== .. image:: https://secure.travis-ci.org/mattupstate/flask-security.png?branch=develop Flask-Security quickly adds security features to your Flask application. Resources --------- - `Documentation <http://packages.python.org/Flask-Security/>`_ - `Issue Tracker <http://github.com/mattupstate/flask-security/issues>`_ - `Code <http://github.com/mattupstate/flask-security/>`_ - `Development Version <http://github.com/mattupstate/flask-security/zipball/develop#egg=Flask-Security-dev>`_
Languages
Python
95.2%
HTML
4.8%