First published: Thu Sep 24 2020(Updated: )
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joplin Project Joplin | >=1.0.190<=1.0.245 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15930 is a Cross-Site Scripting (XSS) vulnerability in Joplin desktop 1.0.190 to 1.0.245 that allows arbitrary code execution via a malicious HTML embed tag.
The severity of CVE-2020-15930 is medium (6.1).
CVE-2020-15930 affects Joplin desktop versions 1.0.190 to 1.0.245.
To fix CVE-2020-15930, it is recommended to update Joplin desktop to version 1.1.4 or later.
CWE-79 is a Common Weakness Enumeration category for Improper Neutralization of Input During Web Page Generation vulnerability, which is relevant to CVE-2020-15930.