← Back

CVE-2023-42222

nvd nist
Published: Sep 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Affected (1)

1 product
Webcatalog
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 49.0

Timeline

No history available yet.