PT-2022-18809 · Unknown · Turtlapp Turtle Note

Muhammad Samak

+1

·

Published

2022-04-28

·

Updated

2022-05-06

·

CVE-2022-28101

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Turtlapp Turtle Note version 0.7.2.6
Description The issue allows attackers to execute HTML injection due to the lack of filtering of the tag during markdown parsing.
Recommendations For version 0.7.2.6, as a temporary workaround, consider disabling markdown parsing until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28101

Affected Products

Turtlapp Turtle Note