CVE-2022-45598: XSS
Published Jan 31, 2023
·Updated
Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.
Affected Software
1 affected component
Joplin Project Joplin<2.9.17
Remediation
Event History
Jan 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-45598?
CVE-2022-45598 is a Cross Site Scripting vulnerability in the Joplin Desktop App before v2.9.17.
2
How does CVE-2022-45598 allow an attacker to execute arbitrary code?
CVE-2022-45598 allows an attacker to execute arbitrary code by exploiting improper sanitization in the Joplin Desktop App.
3
What is the severity of CVE-2022-45598?
CVE-2022-45598 has a severity rating of medium with a CVSS score of 6.1.
4
How can I fix CVE-2022-45598?
To fix CVE-2022-45598, update the Joplin Desktop App to version 2.9.17 or later.
5
What is CWE-79?
CWE-79 is a vulnerability class for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').