9
CVSSv3

CVE-2020-35717

Published: 01/01/2021 Updated: 07/01/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

zonote up to and including 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

electronjs zonote

Github Repositories

Showcase repository for CVE-2020-35717

CVE-2020–35717 zonote allows XSS via crafted note, with resultant Remote Code Execution (because Nodejs integration is enabled) Steps to exploit the vulnerability Download any zonote affected version Open zonote app Import xss-rceznt in zonote via Menu > Open Hover over the different links in imported notes