CVE-2024-40643: Joplin has a parsing error leading to Cross-site Scripting (XSS)
Published Sep 9, 2024
·Updated
Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.
Affected Software
1 affected component
Joplin Project Joplin<3.0.15
Remediation
Event History
Sep 9, 2024
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-40643?
CVE-2024-40643 has a medium severity rating due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-40643?
To mitigate CVE-2024-40643, update Joplin to version 3.0.15 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2024-40643?
CVE-2024-40643 is classified as a cross-site scripting (XSS) vulnerability affecting Joplin.
4
Which versions of Joplin are affected by CVE-2024-40643?
CVE-2024-40643 affects Joplin versions prior to 3.0.15.
5
Can CVE-2024-40643 be exploited remotely?
Yes, CVE-2024-40643 can be exploited remotely if a user interacts with malicious content within affected Joplin applications.