First published: Thu Jun 16 2022(Updated: )
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joplin Project Joplin | <1.8.5 | |
npm/joplin | <1.8.5 | 1.8.5 |
<1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2021-33295.
CVE-2021-33295 has a severity rating of 5.4 (medium).
The Joplin Desktop App version before 1.8.5 is affected by CVE-2021-33295.
Attackers can exploit CVE-2021-33295 by executing arbitrary code through Cross Site Scripting (XSS) due to improper sanitizing of html in the Joplin Desktop App.
To fix CVE-2021-33295, update your Joplin Desktop App to version 1.8.5 or higher.