PT-2024-21799 · Unknown · Docassemble

·

CVE-2024-27291

·

Published

2024-02-29

·

Updated

2026-07-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Docassemble versions prior to 1.4.97
Description The issue allows an attacker to create a URL that acts as an open redirect. This can potentially be used to redirect users to malicious websites.
Recommendations For versions prior to 1.4.97, update to version 1.4.97 or later to resolve the issue. As a temporary workaround, manually apply the changes of the patch and restart the server.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-27291
GHSA-7WXF-R2QV-9XWR
PYSEC-2026-1310

Affected Products

Docassemble