Description
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
Recommendation
Update the joplin
package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.9.17
- Patched version(s): 2.9.17
References
Related Issues
- Prototype Pollution in lodash (GHSA-jf85-cpcp-j695) 4 - CVE-2019-10744
- Prototype Pollution in lodash (GHSA-jf85-cpcp-j695) 2 - CVE-2019-10744
- Passbolt Browser Extension leaks password information - CVE-2024-33669
- Remote Code Execution on click of <a> Link in markdown preview - CVE-2024-49362
- Tags:
- npm
- joplin
Anything's wrong? Let us know Last updated on February 08, 2023