Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3799-7g8h-9xh6

Опубликовано: 07 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

EPSS

Процентиль: 0%
0.00088
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
15 дней назад

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

EPSS

Процентиль: 0%
0.00088
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-79