Lucene search

K
cveGitHub_MCVE-2023-49281
HistoryDec 01, 2023 - 10:15 p.m.

CVE-2023-49281

2023-12-0122:15:10
CWE-601
GitHub_M
web.nvd.nist.gov
11
calendarinho
open source
calendaring
application
large teams
consultants
open redirect
vulnerability
patch
commit
phishing
information theft
reputational damage
nvd

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.4%

Calendarinho is an open source calendaring application to manage large teams of consultants. An Open Redirect issue occurs when a web application redirects users to external URLs without proper validation. This can lead to phishing attacks, where users are tricked into visiting malicious sites, potentially leading to information theft and reputational damage to the website used for redirection. The problem is has been patched in commit 15b2393. Users are advised to update to a commit after 15b2393. There are no known workarounds for this vulnerability.

Affected configurations

Nvd
Vulners
Node
cainorcalendarinhoRange<2023-10-11
VendorProductVersionCPE
cainorcalendarinho*cpe:2.3:a:cainor:calendarinho:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Cainor",
    "product": "Calendarinho",
    "versions": [
      {
        "version": "< 15b2393",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.4%

Related for CVE-2023-49281