Lucene search

K
nvd[email protected]NVD:CVE-2023-49281
HistoryDec 01, 2023 - 10:15 p.m.

CVE-2023-49281

2023-12-0122:15:10
CWE-601
web.nvd.nist.gov
1
calendarinho
open redirect
phishing
information theft
commit 15b2393
update

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.4%

Calendarinho is an open source calendaring application to manage large teams of consultants. An Open Redirect issue occurs when a web application redirects users to external URLs without proper validation. This can lead to phishing attacks, where users are tricked into visiting malicious sites, potentially leading to information theft and reputational damage to the website used for redirection. The problem is has been patched in commit 15b2393. Users are advised to update to a commit after 15b2393. There are no known workarounds for this vulnerability.

Affected configurations

Nvd
Node
cainorcalendarinhoRange<2023-10-11
VendorProductVersionCPE
cainorcalendarinho*cpe:2.3:a:cainor:calendarinho:*:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.4%

Related for NVD:CVE-2023-49281