Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37394
HistoryOct 03, 2022 - 5:46 p.m.

Remote Code Execution (RCE)

2022-10-0317:46:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
153
remote code execution
joplin
vulnerability
unvalidated links

0.001 Low

EPSS

Percentile

36.2%

Joplin is vulnerable to remote code execution. The vulnerability is due to the application not validating the schema or protocol of existing links. An attacker can upload a malicious markdown file with links, which will be opened by shell.openExternal() when a user opens the markdown file, resulting in remote code execution.

CPENameOperatorVersion
joplinle2.8.1
joplinle2.8.1

0.001 Low

EPSS

Percentile

36.2%

Related for VERACODE:37394