漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
Notesnook vulnerable to RCE via stored XSS in Note History diff viewer
漏洞信息
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using `dangerouslySetInnerHTML` without secure handling. When combined with the full backup and restore feature in the desktop application, this becomes remote code execution because Electron is configured with `nodeIntegration: true` and `contextIsolation: false`. Version 3.3.11 patches the issue.
漏洞信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
漏洞
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞
Notesnook 代码注入漏洞
漏洞信息
Notesnook是Streetwriters开源的一个端到端加密的笔记应用。 Notesnook Web/Desktop 3.3.11之前版本存在代码注入漏洞,该漏洞源于笔记历史比较查看器中存储的跨站脚本漏洞,可能导致在桌面应用程序中升级为远程代码执行。
漏洞信息
N/A
漏洞
N/A