CVE-2020-15930: XSS
Published Sep 24, 2020
·Updated
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
Affected Software
1 affected component
Joplin Project Joplin>=1.0.190<=1.0.245
Event History
Sep 24, 2020
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15930?
CVE-2020-15930 is a Cross-Site Scripting (XSS) vulnerability in Joplin desktop 1.0.190 to 1.0.245 that allows arbitrary code execution via a malicious HTML embed tag.
2
What is the severity of CVE-2020-15930?
The severity of CVE-2020-15930 is medium (6.1).
3
How does CVE-2020-15930 affect Joplin desktop?
CVE-2020-15930 affects Joplin desktop versions 1.0.190 to 1.0.245.
4
How can I fix CVE-2020-15930?
To fix CVE-2020-15930, it is recommended to update Joplin desktop to version 1.1.4 or later.
5
What is CWE-79?
CWE-79 is a Common Weakness Enumeration category for Improper Neutralization of Input During Web Page Generation vulnerability, which is relevant to CVE-2020-15930.