{"id":"GHSA-cgc7-mwp4-3ccx","summary":"Cross-site Scripting in Joplin","details":"An XSS issue in Joplin desktop allows arbitrary code execution via a malicious HTML embed tag.","aliases":["CVE-2020-15930"],"modified":"2023-11-08T04:02:38.583521Z","published":"2021-05-07T16:29:05Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-04-28T12:42:46Z","nvd_published_at":"2020-09-24T19:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15930"},{"type":"WEB","url":"https://github.com/laurent22/joplin/issues/3552"},{"type":"WEB","url":"https://github.com/laurent22/joplin/commit/57d750bc9aeb0f98d53ed4b924458b54984c15ff"},{"type":"WEB","url":"https://github.com/laurent22/joplin/releases/tag/v1.1.4"},{"type":"WEB","url":"http://packetstormsecurity.com/files/159316/Joplin-1.0.245-Cross-Site-Scripting-Code-Execution.html"}],"affected":[{"package":{"name":"joplin","ecosystem":"npm","purl":"pkg:npm/joplin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.190"},{"fixed":"1.1.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-cgc7-mwp4-3ccx/GHSA-cgc7-mwp4-3ccx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}