CVE-2020-15930
MEDIUMJoplin 1.0.190-1.0.245 - Cross-Site Scripting via HTML Embed Tag
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-15930. PoCs published by Ademar Nowasky Junior.
AI-analyzed exploit summary This exploit leverages an XSS vulnerability in Joplin's note rendering engine, combined with improper Node.js integration in child windows, to achieve arbitrary code execution. The PoC includes a payload for local execution and a remote attack vector via Joplin's unauthenticated API.
Description
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
Exploits (1)
This exploit leverages an XSS vulnerability in Joplin's note rendering engine, combined with improper Node.js integration in child windows, to achieve arbitrary code execution. The PoC includes a payload for local execution and a remote attack vector via Joplin's unauthenticated API.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N