Junglewise Threat Intelligence

CVE-2020-15930: Joplin cross-site scripting in HTML embed tag

CVE-2020-15930 · Severity: low · CVSS 3.1 · Published 2021-05-07

Technologies: Joplin. Vendors: Joplin.

Executive brief

Joplin is a note-taking application for managing personal and business documents. An attacker can craft a malicious HTML embed tag in a note that, when opened by a user, allows arbitrary code execution on the victim's system, potentially compromising all stored notes and data.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw classified as CWE-79 in Joplin's desktop application. The vulnerable component improperly sanitizes HTML embed tags in note content, allowing arbitrary code injection. Attack requires user interaction (opening a malicious note), but no authentication is needed beyond the user having access to Joplin. An attacker can execute arbitrary JavaScript code in the context of the Joplin application, potentially leading to code execution on the victim's system. The vulnerability was fixed in version 1.1.7, with the affected range being 1.0.190 through 1.1.6.

Affected products

  • Joplin Joplin 1.0.190 to 1.1.6

Timeline

  • 2020-09-24: disclosed: Vulnerability published on NVD
  • 2021-05-07: patched: Advisory published; fix available in version 1.1.7

References

Related threats