PT-2022-15834 · Habitica · Habitica

Sabrecat

·

Published

2022-06-22

·

Updated

2022-06-29

·

CVE-2022-23078

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Habitica versions v4.119.0 through v4.232.2
Description The issue concerns an open redirect via the login page.
Recommendations For versions v4.119.0 through v4.232.2, update to a version that is not within this range to resolve the issue. As a temporary workaround, consider restricting access to the login page until a patch is available.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23078

Affected Products

Habitica