Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcw2-q3mm-wc8g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.

EPSS

Процентиль: 79%
0.01275
Низкий

Связанные уязвимости

CVSS3: 9.6
nvd
больше 5 лет назад

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.

EPSS

Процентиль: 79%
0.01275
Низкий