Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-01488
HistoryNov 07, 2022 - 12:00 a.m.

Zettlr input validation error vulnerability

2022-11-0700:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
zettlr
input validation
vulnerability
csp policy
content validation
local file viewing
attacker

0.001 Low

EPSS

Percentile

31.7%

Zettlr is the most comprehensive editor for professionally editing Markdown files. version 2.3.0 of Zettlr is vulnerable to an input validation error, which stems from the fact that the application has no CSP policy and does not properly validate content before rendering markdown files, which could be exploited by an attacker to view arbitrary files locally.

CPENameOperatorVersion
zettlr zettlreq2.3.0

0.001 Low

EPSS

Percentile

31.7%

Related for CNVD-2023-01488