Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2024-49362

почти 2 года назад

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability allows the execution of untrusted HTML content within the Electron window, which has full access to Node.js APIs, enabling arbitrary shell command execution.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2024-49362

почти 2 года назад

Joplin is a free, open source note taking and to-do application. Jopli ...

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-hff8-hjwv-j9q7

почти 2 года назад

Remote Code Execution on click of <a> Link in markdown preview

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability allows the execution of untrusted HTML content within the Electron window, which has full access to Node.js APIs, enabling arbitrary shell command execution.

CVSS3: 7.7
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-49362

Joplin is a free, open source note taking and to-do application. Jopli ...

CVSS3: 7.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-hff8-hjwv-j9q7

Remote Code Execution on click of <a> Link in markdown preview

CVSS3: 7.7
1%
Низкий
почти 2 года назад

Уязвимостей на страницу