Логотип exploitDog
bind:CVE-2024-49362
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-49362

Количество 3

Количество 3

nvd логотип

CVE-2024-49362

около 1 года назад

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability allows the execution of untrusted HTML content within the Electron window, which has full access to Node.js APIs, enabling arbitrary shell command execution.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-49362

около 1 года назад

Joplin is a free, open source note taking and to-do application. Jopli ...

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-hff8-hjwv-j9q7

около 1 года назад

Remote Code Execution on click of <a> Link in markdown preview

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability allows the execution of untrusted HTML content within the Electron window, which has full access to Node.js APIs, enabling arbitrary shell command execution.

CVSS3: 7.7
2%
Низкий
около 1 года назад
debian логотип
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Jopli ...

CVSS3: 7.7
2%
Низкий
около 1 года назад
github логотип
GHSA-hff8-hjwv-j9q7

Remote Code Execution on click of <a> Link in markdown preview

CVSS3: 7.7
2%
Низкий
около 1 года назад

Уязвимостей на страницу