Description
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
Recommendation
Update the joplin package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.9.17
- Patched version(s): 2.9.17
References
Related Issues
- node-red-dashboard vulnerable to Cross-site Scripting - CVE-2022-3783
- grapesjs before 0.19.5 vulnerable to Cross-site Scripting - CVE-2022-21802
- Jodit Editor vulnerable to Cross-site Scripting - jodit - CVE-2022-23461
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
You might also like:
- Tags:
- npm
- joplin
Anything's wrong? Let us know Last updated on February 08, 2023


