CVE-2023-42222
WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
- Affected products
- Electron, Webcatalog
- Webcatalog
- < 49.0
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.4% (70th percentile)
- NVD status
- Modified
- Published
- 2023-09-28
CVE-2023-42222 at NVD
4 known exploits for CVE-2023-42222
Proof-of-concept code and exploit modules indexed by Sploitus