WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-09-28T00:00:00

Updated: 2024-02-02T17:06:22.717365

Reserved: 2023-09-08T00:00:00


Link: CVE-2023-42222

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-09-28T03:15:11.643

Modified: 2024-02-02T17:15:10.690


Link: CVE-2023-42222

JSON object: View

cve-icon Redhat Information

No data.