CVE-2020-9038: XSS
Published Feb 17, 2020
·Updated
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
Affected Software
1 affected component
Joplin Project Joplin<=1.0.184
Remediation
Event History
Feb 17, 2020
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-9038?
CVE-2020-9038 has a moderate severity rating due to its potential for arbitrary file read via XSS.
2
How do I fix CVE-2020-9038?
To fix CVE-2020-9038, update Joplin to version 1.0.185 or later.
3
What versions of Joplin are affected by CVE-2020-9038?
CVE-2020-9038 affects Joplin versions up to and including 1.0.184.
4
What kind of attack does CVE-2020-9038 allow?
CVE-2020-9038 allows attackers to exploit a cross-site scripting vulnerability to perform arbitrary file reads.
5
Is there a workaround for CVE-2020-9038 until I can update?
Currently, the best workaround for CVE-2020-9038 is to limit the use of untrusted scripts in Joplin.