CVE-2021-33295: XSS
Published Jun 16, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
Affected Software
2 affected componentsFixes available
Joplin Project Joplin<1.8.5
npm/joplin<1.8.5
1.8.5
Remediation
Event History
Jun 16, 2022
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
Description
Jun 17, 2022
Advisory Published
via GitHub·12:01 AM
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2021-33295.
2
What is the severity rating of CVE-2021-33295?
CVE-2021-33295 has a severity rating of 5.4 (medium).
3
Which software is affected by CVE-2021-33295?
The Joplin Desktop App version before 1.8.5 is affected by CVE-2021-33295.
4
How can attackers exploit this vulnerability?
Attackers can exploit CVE-2021-33295 by executing arbitrary code through Cross Site Scripting (XSS) due to improper sanitizing of html in the Joplin Desktop App.
5
How can I fix CVE-2021-33295?
To fix CVE-2021-33295, update your Joplin Desktop App to version 1.8.5 or higher.