Описание
WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
Ссылки
- ExploitThird Party Advisory
- Release Notes
- Third Party Advisory
- ExploitThird Party Advisory
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 49.0 (исключая)
cpe:2.3:a:webcatalog:webcatalog:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04367
Низкий
8.8 High
CVSS3
Дефекты
NVD-CWE-Other
Связанные уязвимости
CVSS3: 8.8
github
больше 2 лет назад
WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
EPSS
Процентиль: 89%
0.04367
Низкий
8.8 High
CVSS3
Дефекты
NVD-CWE-Other