PT-2021-11830 · Zonote · Zonote

Published

2021-01-01

·

Updated

2021-01-07

·

CVE-2020-35717

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: zonote versions through 0.4.0
Description: The issue allows for Cross-Site Scripting (XSS) via a crafted note, which can result in Remote Code Execution. This is possible because nodeIntegration in webPreferences is set to true.
Recommendations: For versions through 0.4.0, update to a version where nodeIntegration in webPreferences is set to false or apply other mitigations to prevent XSS attacks. As a temporary workaround, consider disabling the nodeIntegration in webPreferences until a patch is available. Restrict access to crafted notes to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35717

Affected Products

Zonote