CVE-2023-49281
Dashboard / Vulnerabilities / CVE-2023-49281
Summary: Open Redirect in Login Function of Calendarinho
Details: Calendarinho is an open source calendaring application to manage large teams of consultants. An Open Redirect issue occurs when a web application redirects users to external URLs without proper validation. This can lead to phishing attacks, where users are tricked into visiting malicious sites, potentially leading to information theft and reputational damage to the website used for redirection. The problem is has been patched in commit `15b2393`. Users are advised to update to a commit after `15b2393`. There are no known workarounds for this vulnerability.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49281.json, https://github.com/Cainor/Calendarinho/security/advisories/GHSA-g2gp-x888-6xrj, https://nvd.nist.gov/vuln/detail/CVE-2023-49281, https://github.com/Cainor/Calendarinho/commit/15b2393efd69101727d27a4e710880ce46e84d70, https://github.com/Cainor/Calendarinho/commit/9a0174bef939565a76cbe7762996ecddca9ba55e, https://github.com/Cainor/Calendarinho/commit/c77defeb0103c1f7a4709799b8751aaeb0d09eed
Affected packages
Package
Name:
Purl:
