Medium severity6.1NVD Advisory· Published May 13, 2019· Updated Jun 17, 2026
CVE-2018-18524
CVE-2018-18524
Description
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Evernote/Evernotedescription
Patches
Vulnerability mechanics
References
2- paper.seebug.org/737/nvdExploitThird Party Advisory
- evernote.com/intl/en/security/updatesnvdVendor Advisory
News mentions
0No linked articles in our index yet.