Joplin.MdToHtml.XSS
Description
This indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in Joplin Project Joplin.
This vulnerability is due to improper validation and escaping of the language selector in markdown code block element. A remote attacker could exploit this vulnerability by enticing a victim to open a crafted markdown document. Successful exploitation could allow the attacker to execute arbitrary code under the security context of the user.
Affected Products
Joplin Project Joplin prior to v2.9.17
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/laurent22/joplin/releases/tag/v2.9.17
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |