8.8
CVE-2023-42222
- EPSS 4.37%
- Veröffentlicht 28.09.2023 03:15:11
- Zuletzt bearbeitet 21.11.2024 08:22:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webcatalog ≫ Webcatalog Version < 49.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.37% | 0.885 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|