疑似Oday
Joplin Server installations are vulnerable to default administrative credentials. The system ships with a default admin account using the credentials admin@localhost:admin. Attackers can leverage these default credentials to gain administrative access to the Joplin Server instance, potentially compromising sensitive user data and system functionality.
id: joplin-default-login
info:
name: Joplin - Default Login
author: pussycat0x
severity: high
...