CVE-2021-33295

MEDIUM5.4EPSS 0.26%

Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags

Published: 6/17/2022Modified: 4/23/2024
Also known as:GHSA-phj8-2p6x-hq5r

Description

Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (5)