6.1
CVSSv3

CVE-2020-28249

Published: 06/11/2020 Updated: 12/11/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joplin project joplin 1.2.6

Exploits

Joplin version 126 suffers from a cross site scripting vulnerability ...

Github Repositories

Exploit Title: Joplin 126 Cross Site Scripting Date: 2020-10-27 Exploit Author: Philip Holbrook (@fhlipZero) Vendor Homepage: joplinapporg/ Software Link: githubcom/laurent22/joplin/releases/tag/v126 Version: 126 Tested on: Windows / Mac CVE : CVE-2020-28249 References: PENDING next release Technical Details An XSS issue in Joplin for de