CVE-2022-23078: Habitica - Open redirect in login page
Published Jun 22, 2022
·Updated
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
Affected Software
1 affected component
habitica habitica>=4.119.0<4.233.0
Remediation
Information
Update version to v4.233.0 or later
Event History
Jun 22, 2022
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-23078?
CVE-2022-23078 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-23078?
To fix CVE-2022-23078, update Habitica to version 4.233.0 or later.
3
What type of vulnerability is CVE-2022-23078?
CVE-2022-23078 is an open redirect vulnerability found in the Habitica login page.
4
Which versions of Habitica are affected by CVE-2022-23078?
Habitica versions v4.119.0 through v4.232.2 are affected by CVE-2022-23078.
5
Can CVE-2022-23078 lead to phishing attacks?
Yes, CVE-2022-23078 can potentially be exploited to facilitate phishing attacks.