Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Joplin 输入验证错误漏洞
Vulnerability Description
Joplin是一款开源的笔记和待办事项应用程序。 Joplin 2.8.8版本存在输入验证错误漏洞。攻击者利用该漏洞可以远程执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A