Page 3 of 12 results (0.004 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Joplin before 2.0.9 allows XSS via button and form in the note body. Joplin versiones anteriores a 2.0.9, permite un ataque XSS por medio del button y form en el cuerpo de la nota • https://github.com/laurent22/joplin/commit/feaecf765368f2c273bea3a9fa641ff0da7e6b26 https://github.com/laurent22/joplin/releases/tag/v2.0.9 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. Un problema de tipo XSS en Joplin Desktop versiones 1.0.190 hasta 1.0.245, permite una ejecución de código arbitrario por medio de una etiqueta de inserción HTML maliciosa. Joplin version 1.0.245 suffers from a cross site scripting vulnerability that can lead to allowing for remote code execution. • https://www.exploit-db.com/exploits/48837 http://packetstormsecurity.com/files/159316/Joplin-1.0.245-Cross-Site-Scripting-Code-Execution.html https://github.com/laurent22/joplin/issues/3552 https://github.com/laurent22/joplin/releases/tag/v1.1.4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •