SabreCat

2 exploits Active since Jun 2022
CVE-2022-23077 WRITEUP MEDIUM WRITEUP
habitica 4.119.0-4.232.2 - DOM-Based Cross-Site Scripting via Login Page
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
CVSS 6.1
CVE-2022-23078 WRITEUP WRITEUP
habitica 4.119.0-4.232.2 - Open Redirect via Login Page
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.