Vulnerabilities/

Joplin Vulnerable to Cross-site Scripting in Note Content

Severity:
Medium

Description

Joplin version prior to 1.0.90 contains a Cross-site Scripting (XSS) evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - information on the fix can be found here https://github.

Recommendation

Update the joplin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
joplin
Anything's wrong? Let us know Last updated on April 23, 2024

This issue is available in SmartScanner Professional

See Pricing