CVE-2023-42222

HIGH

WebCatalog <49.0 - XSS

Title source: llm
STIX 2.1

Description

WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

Exploits (1)

nomisec WRITEUP 3 stars
by itssixtyn3in · poc
https://github.com/itssixtyn3in/CVE-2023-42222

Scores

CVSS v3 8.8
EPSS 0.0437
EPSS Percentile 89.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
webcatalog/webcatalog < 49.0
Published Sep 28, 2023
Tracked Since Feb 18, 2026