Lucene search

K
cvelistFluid AttacksCVELIST:CVE-2022-40277
HistorySep 30, 2022 - 4:20 p.m.

CVE-2022-40277

2022-09-3016:20:59
Fluid Attacks
www.cve.org
1
joplin
version 2.8.8
remote attackers
execute arbitrary commands
malicious markdown file
shell.openexternal function

0.001 Low

EPSS

Percentile

36.2%

Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the ‘shell.openExternal’ function.

CNA Affected

[
  {
    "product": "Joplin",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "2.8.8"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

36.2%

Related for CVELIST:CVE-2022-40277