CVE-2023-37511
LOWHCL Traveler To-Do < 12.0.6 - Insecure Web Content Loading via App Transport Security Misconfiguration
Title source: llmDescription
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be achieved.
References (1)
Core 1
Core References
Scores
CVSS v3
3.5
EPSS
0.0029
EPSS Percentile
52.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (1)
hcltech/traveler_to_do
< 12.0.6
Published
Aug 11, 2023
Tracked Since
Feb 18, 2026