Desktop App
by Leanote
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26158 | Cri | 0.63 | 9.6 | 0.02 | Sep 30, 2020 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration. | ||
| CVE-2020-26157 | Cri | 0.63 | 9.6 | 0.02 | Sep 30, 2020 | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration. | ||
| CVE-2021-43721 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : | ||
| CVE-2017-1000492 | Med | 0.00 | 6.1 | 0.01 | Jan 3, 2018 | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration |
- risk 0.63cvss 9.6epss 0.02
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.
- risk 0.63cvss 9.6epss 0.02
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.
- risk 0.40cvss 6.1epss 0.01
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload :
- risk 0.00cvss 6.1epss 0.01
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration