4 results (0.007 seconds)

CVSS: 8.2EPSS: 0%CPEs: 4EXPL: 1

19 Aug 2023 — Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian. • https://obsidian.md/changelog/2023-05-03-desktop-v1.2.8 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 0

20 May 2023 — Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page. • https://forum.obsidian.md/t/obsidian-release-v1-2-2-insider-build/57488 •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 2

22 Jan 2023 — A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended feature." Un problema de inyección de encabezado de host en la página de inicio de sesión de Plesk Obsidian hasta 18.0.49 permite a los atacantes redirigir a los usuarios a sitios web maliciosos a través de un encabezado de solicitud de ... • https://github.com/Cappricio-Securities/CVE-2023-24044 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

25 Jul 2022 — Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL. Obsidian versiones 0.14.x y 0.15.x anteriores a 0.15.,5 permite la ejecución de código remota obsidian://hook-get-address porque es usado window.open sin comprobar la URL • https://forum.obsidian.md/t/possible-remote-code-execution-through-obsidian-uri-scheme/39743 • CWE-20: Improper Input Validation •