vendor:
Joplin Desktop
by:
Javier Olmedo
5.4
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Joplin Desktop
Affected Version From: 1.0.184
Affected Version To: 1.0.184
Patch Exists: YES
Related CWE: CVE-2020-9038
CPE: a:laurent22:joplin:1.0.184
Platforms Tested: Windows
2020
Joplin Desktop 1.0.184 – Cross-Site Scripting
Joplin Desktop version 1.0.184 and before are affected by Cross-Site Scripting vulnerability through the malicious note. This allows a malicious user to read arbitrary files of the system.
Mitigation:
Upgrade to patched version 1.0.185