Описание
Joplin is a free, open source note taking and to-do application. A Cross-site Scripting (XSS) vulnerability allows an untrusted note opened in safe mode to execute arbitrary code. packages/renderer/MarkupToHtml.ts renders note content in safe mode by surrounding it with
Загрузка...
, without escaping any interior HTML tags. Thus, an attacker can create a note that closes the openingЗагрузка...
Ссылки
- Technical Description
- ExploitVendor Advisory
- Technical Description
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.12.9 (исключая)
cpe:2.3:a:joplin_project:joplin:*:*:*:*:*:-:*:*
EPSS
Процентиль: 66%
0.0051
Низкий
8.2 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 8.2
debian
больше 1 года назад
Joplin is a free, open source note taking and to-do application. A Cro ...
EPSS
Процентиль: 66%
0.0051
Низкий
8.2 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79