Description
The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.
Remediation
References
Related Vulnerabilities
Django Resource Management Errors Vulnerability (CVE-2015-5145)
XWiki Improper Privilege Management Vulnerability (CVE-2023-26475)
WordPress Plugin xPinner Lite Multiple Vulnerabilities (2.2)
WordPress Plugin Membership 2 Unspecified Vulnerability (4.0.0.2)
WordPress Plugin Helpie FAQ-WordPress FAQ Accordion Security Bypass (0.7)