Skip to main content

CVE-2020-35717

Description

zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

nvd
CVE ID: CVE-2020-35717
Base Score: 9.0
Base Severity: CRITICAL
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Impact Score: 6.0
Exploitability Score: 2.3

Proof Of Concept

hmartos

Showcase repository for CVE-2020-35717

Refrence: GitHub

Redfox-Secuirty

Refrence: GitHub

Refrence: NVD