CVE-2022-36677: XSS
Published Jan 5, 2024
·Updated
Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.
Affected Software
2 affected components
Obsidian Mind Map
Lynchjames Obsidian Mind Map=1.1.0
Event History
Jan 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36677?
CVE-2022-36677 is rated as a critical vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2022-36677?
To fix CVE-2022-36677, update to the latest version of Obsidian Mind Map that addresses this vulnerability.
3
What types of attacks can exploit CVE-2022-36677?
CVE-2022-36677 allows attackers to execute arbitrary code by uploading a malicious document, leading to a full system compromise.
4
Who is affected by CVE-2022-36677?
CVE-2022-36677 affects users of Obsidian Mind Map version 1.1.0.
5
When was CVE-2022-36677 disclosed?
CVE-2022-36677 was disclosed in 2022, highlighting a significant security risk for users of the affected software.