CVE-2024-40643 - Joplin Cross-Site Scripting (XSS)
CVE ID : CVE-2024-40643
Published : Sept. 9, 2024, 3:15 p.m. | 17 minutes ago
Description : Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 9, 2024, 3:15 p.m. | 17 minutes ago
Description : Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...