PT-2021-11830 · Zonote · Zonote
Published
2021-01-01
·
Updated
2021-01-07
·
CVE-2020-35717
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
zonote versions through 0.4.0
Description:
The issue allows for Cross-Site Scripting (XSS) via a crafted note, which can result in Remote Code Execution. This is possible because
nodeIntegration in webPreferences is set to true.Recommendations:
For versions through 0.4.0, update to a version where
nodeIntegration in webPreferences is set to false or apply other mitigations to prevent XSS attacks.
As a temporary workaround, consider disabling the nodeIntegration in webPreferences until a patch is available.
Restrict access to crafted notes to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zonote