CVE-2020-35717

Published
View on NVD ↗
CVSS v3
9
CRITICAL
CVSS v2
3.5
LOW
Affected
2
PROJECTS

Description

zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

Cross-platform desktop note-taking app. Sticky notes with Markdown and Tabs. All in one .txt file.
GitHubGitHub
317
Showcase repository for CVE-2020-35717
GitHubGitHub
1