#VU103727 Cross-site scripting in Joplin - CVE-2025-24028
Published: February 10, 2025
Joplin
Joplinapp
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Rich Text Editor. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- https://github.com/laurent22/joplin/commit/2a058ed8097c2502e152b26394dc1917897f5817
- https://github.com/laurent22/joplin/commit/9b505395918bc923f34fe6f3b960bb10e8cf234e
- https://github.com/laurent22/joplin/security/advisories/GHSA-5w3c-wph9-hq92
- https://joplinapp.org/help/dev/spec/note_viewer_isolation