MEDIUM5.4
GHSA-phj8-2p6x-hq5r
Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags
Quick fix
GHSA-phj8-2p6x-hq5r — joplin: upgrade to the fixed version with the command below.
npm install joplin@1.8.5Details
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-33295[ADVISORY]
- https://github.com/laurent22/joplin/commit/9c20d5947d1fa4678a8b640792ff3d31224f0adf[WEB]
- https://github.com/laurent22/joplin[PACKAGE]
- https://github.com/laurent22/joplin/releases/tag/v1.8.5[WEB]
- https://the-it-wonders.blogspot.com/2021/05/joplin-app-desktop-version-vulnerable.html[WEB]