Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-44689

Опубликовано: 11 окт. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:e-gov:e-gov:*:*:*:*:*:macos:*:*
Версия до 1.1.1.0 (исключая)
cpe:2.3:a:e-gov:e-gov:*:*:*:*:*:windows:*:*
Версия до 2.1.1.0 (исключая)

EPSS

Процентиль: 17%
0.00056
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.

EPSS

Процентиль: 17%
0.00056
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862