Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36496
HistoryJul 26, 2022 - 5:18 a.m.

Cross-site Scripting (XSS)

2022-07-2605:18:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
joplin
cross-site scripting
vulnerability
string-utils.js
malicious javascript

0.002 Low

EPSS

Percentile

53.6%

joplin is vulnerable to cross-site scripting. The vulnerability exists because the surroundKeywords function of string-utils.js does not properly escape the malicious html codes in valueRegex and value parameters, allowing an attacker to inject and execute malicious javascript.

CPENameOperatorVersion
joplinle2.8.1
joplinle2.8.1

0.002 Low

EPSS

Percentile

53.6%

Related for VERACODE:36496