{"id":"GHSA-q26w-wjj2-22vv","summary":"Cross-site scripting in Joplin","details":"Joplin allows XSS via a LINK element in a note.","aliases":["CVE-2020-28249"],"modified":"2023-11-08T04:03:24.283188Z","published":"2021-05-10T18:47:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-04-20T19:38:53Z","nvd_published_at":"2020-11-06T07:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28249"},{"type":"WEB","url":"https://github.com/laurent22/joplin/commit/fd90a490c0e5cacd17bfe0ffc422be1d2a9b1c13"},{"type":"WEB","url":"https://github.com/fhlip0/JopinXSS"},{"type":"WEB","url":"https://github.com/laurent22/joplin/releases/tag/v1.3.11"},{"type":"WEB","url":"https://www.npmjs.com/package/joplin"}],"affected":[{"package":{"name":"joplin","ecosystem":"npm","purl":"pkg:npm/joplin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-q26w-wjj2-22vv/GHSA-q26w-wjj2-22vv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}