Joplin Insecure Note Taking App Vulnerable to XSS Attack
CVE-2024-40643
9.6CRITICAL
What is CVE-2024-40643?
The Joplin note-taking application is impacted by a cross-site scripting (XSS) vulnerability due to improper handling of certain HTML tags. When '<' is followed by a character that is not a letter, the application does not recognize this as a valid HTML tag. This oversight allows an attacker to inject potentially harmful scripts into user notes, which can compromise the integrity and confidentiality of user data. Users are advised to remain vigilant and apply relevant security updates to mitigate this risk.
Affected Version(s)
joplin < 3.0.15