CVE-2020-35717: XSS
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35717?
CVE-2020-35717 is a vulnerability in zonote versions up to and including 0.4.0 that allows for XSS attacks, leading to remote code execution.
What is the severity of CVE-2020-35717?
CVE-2020-35717 has a severity level of critical, with a severity value of 9.
How does CVE-2020-35717 occur?
CVE-2020-35717 occurs when a crafted note is used to perform XSS, which then allows for remote code execution due to the nodeIntegration setting in webPreferences being enabled.
What software is affected by CVE-2020-35717?
The Electronjs Zonote application with versions up to and including 0.4.0 is affected by CVE-2020-35717.
How can I fix CVE-2020-35717?
To fix CVE-2020-35717, it is recommended to update to a version of zonote that includes a fix for this vulnerability, if available. Additionally, it is advised to review and update the nodeIntegration setting in the webPreferences to mitigate the XSS risk.