Description
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Video Lightbox Cross-Site Scripting (1.9.2)
Family Connections Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-4338)
WordPress Plugin 404 SEO Redirection SQL Injection (1.0)
OpenSSL Inefficient Regular Expression Complexity Vulnerability (CVE-2023-3446)
WordPress Plugin Passster-Password Protection Weak Encoding (3.5.5.5.1)