High
CVSS 7.5
Overview
The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes controller methods even when an @expose decoration is not used, which has unspecified impact and attack vectors.
The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes control...
The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes controller methods even when an @expose decoration is not used, which has unspecified impact and attack vectors.
This vulnerability is rated 🟠 HIGH.
Recommended actions: