Back

CRITICAL

Joplin has a parsing error leading to Cross-site Scripting (XSS)

Published Sep 9, 2024

Description

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character will not be considered html. As such it is possible to do an XSS by putting an "illegal" tag within a tag.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 9, 2024
Updated Sep 9, 2024
Reserved Jul 8, 2024
CISA Vulnrichment
Updated Sep 9, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a