NA

CVE-2022-40277

Published: 30/09/2022 Updated: 04/10/2022
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Joplin version 2.8.8 allows an external malicious user to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joplinapp joplin 2.8.8