WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-09-28T00:00:00

Updated: 2024-08-02T19:16:51.047Z

Reserved: 2023-09-08T00:00:00

Link: CVE-2023-42222

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-09-28T03:15:11.643

Modified: 2024-02-02T17:15:10.690

Link: CVE-2023-42222

cve-icon Redhat

No data.