Description
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
Remediation
References
https://github.com/fhlip0/JopinXSS
https://github.com/laurent22/joplin/releases
Related Vulnerabilities
CVE-2023-47323 Vulnerability in maven package org.silverpeas.core:silverpeas-core-api
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2023-37958 Vulnerability in maven package org.jenkins-ci.plugins:sumologic-publisher
CVE-2023-36477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ckeditor-ui
CVE-2021-23337 Vulnerability in maven package org.webjars.npm:lodash