First published: Fri Jan 01 2021(Updated: )
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Electronjs Zonote | <=0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35717 is a vulnerability in zonote versions up to and including 0.4.0 that allows for XSS attacks, leading to remote code execution.
CVE-2020-35717 has a severity level of critical, with a severity value of 9.
CVE-2020-35717 occurs when a crafted note is used to perform XSS, which then allows for remote code execution due to the nodeIntegration setting in webPreferences being enabled.
The Electronjs Zonote application with versions up to and including 0.4.0 is affected by CVE-2020-35717.
To fix CVE-2020-35717, it is recommended to update to a version of zonote that includes a fix for this vulnerability, if available. Additionally, it is advised to review and update the nodeIntegration setting in the webPreferences to mitigate the XSS risk.