CVE-2023-42222
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
| Vendor | n/a |
| Product | n/a |
| Published | Sep 28, 2023 |
| Last Updated | Aug 2, 2024 |
Stay Ahead of the Next One
Get instant alerts for n/a n/a
Be the first to know when new unknown vulnerabilities affecting n/a n/a are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / n/a
n/a
References
webcatalog.io: https://webcatalog.io/changelog/ electronjs.org: https://www.electronjs.org/docs/latest/tutorial/security#15-do-not-use-shellopenexternal-with-untrusted-content github.com: https://github.com/itssixtyn3in/CVE-2023-42222 packetstormsecurity.com: http://packetstormsecurity.com/files/176957/WebCatalog-48.4-Arbitrary-Protocol-Execution-Code-Execution.html