Description
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
Remediation
References
https://github.com/fhlip0/JopinXSS
https://github.com/laurent22/joplin/releases
Related Vulnerabilities
CVE-2020-26282 Vulnerability in maven package com.browserup:browserup-proxy-rest
CVE-2022-23540 Vulnerability in maven package org.webjars.npm:jsonwebtoken
CVE-2023-0044 Vulnerability in maven package io.quarkus:quarkus-security-webauthn
CVE-2022-25929 Vulnerability in npm package smoothie
CVE-2020-13697 Vulnerability in maven package org.nanohttpd:nanohttpd-nanolets