Description
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
Remediation
References
Related Vulnerabilities
WordPress Plugin Plugmatter Pricing Table Cross-Site Scripting (1.0.32)
WordPress Plugin 3DPrint Lite Cross-Site Scripting (1.9.1.5)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
ReviveAdserver Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7371)