Description
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP People 'wp-people-popup.php' SQL Injection (2.0)
Oracle Database Server Other Vulnerability (CVE-1999-0784)
WordPress Plugin Payment Gateways Caller for WP e-Commerce Local File Inclusion (0.1)
MySQL CVE-2020-2921 Vulnerability (CVE-2020-2921)
WordPress Plugin WP Unique Article Header Image Cross-Site Request Forgery (1.0)