Joplin Insecure Note Taking App Vulnerable to XSS Attack
CVE-2024-40643

9.6CRITICAL

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
9 September 2024

What is CVE-2024-40643?

The Joplin note-taking application is impacted by a cross-site scripting (XSS) vulnerability due to improper handling of certain HTML tags. When '<' is followed by a character that is not a letter, the application does not recognize this as a valid HTML tag. This oversight allows an attacker to inject potentially harmful scripts into user notes, which can compromise the integrity and confidentiality of user data. Users are advised to remain vigilant and apply relevant security updates to mitigate this risk.

Affected Version(s)

joplin < 3.0.15

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-40643 : Joplin Insecure Note Taking App Vulnerable to XSS Attack