WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Webcatalog | Webcatalog | * | 49.0 (excluding) |