Boost Note
by Boost Note
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41392 | Cri | 0.64 | 9.8 | 0.03 | Sep 17, 2021 | static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API. | ||
| CVE-2020-19924 | Med | 0.35 | 5.4 | 0.01 | May 18, 2021 | In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks. |
- risk 0.64cvss 9.8epss 0.03
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
- risk 0.35cvss 5.4epss 0.01
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.