Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v78j-8xxm-8wgf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

EPSS

Процентиль: 79%
0.01275
Низкий

Связанные уязвимости

CVSS3: 9.6
nvd
больше 5 лет назад

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

EPSS

Процентиль: 79%
0.01275
Низкий