vendor:
WebCatalog
by:
ItsSixtyN3in
7.1
CVSS
HIGH
Arbitrary Protocol Execution
918
CWE
Product Name: WebCatalog
Affected Version From: 48.4.0
Affected Version To: 48.7.9
Patch Exists: NO
Related CWE: CVE-2023-42222
CPE: a:webcatalog:webcatalog:48.4.0
Platforms Tested: Windows
2023
WebCatalog 48.4 – Arbitrary Protocol Execution
WebCatalog version 48.4 and earlier does not properly validate URLs before calling the Electron shell.openExternal function, enabling an attacker to execute code via arbitrary protocols when users interact with malicious URLs. This can lead to the bypassing of security mechanisms for delivering malicious files.
Mitigation:
Update WebCatalog to version 48.8 or later to fix this vulnerability. Avoid interacting with unsolicited or suspicious links.