Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-41662

Опубликовано: 24 июл. 2024
Источник: nvd
CVSS3: 8.6
CVSS3: 9.6
EPSS Средний

Описание

VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the VNote note-taking application. This vulnerability allows the injection and execution of arbitrary JavaScript code through which remote code execution can be achieved. A patch for this issue is available at commit f1af78573a0ef51d6ef6a0bc4080cddc8f30a545. Other mitigation strategies include implementing rigorous input sanitization for all Markdown content and utilizing a secure Markdown parser that appropriately escapes or strips potentially dangerous content.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vnote_project:vnote:*:*:*:*:*:*:*:*
Версия до 3.18.1 (включая)

EPSS

Процентиль: 94%
0.12236
Средний

8.6 High

CVSS3

9.6 Critical

CVSS3

Дефекты

CWE-79
CWE-79

EPSS

Процентиль: 94%
0.12236
Средний

8.6 High

CVSS3

9.6 Critical

CVSS3

Дефекты

CWE-79
CWE-79