Vulnerability Description
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Electronjs | Zonote | <= 0.4.0 |
Related Weaknesses (CWE)
References
- https://github.com/hmartos/cve-2020-35717ExploitThird Party Advisory
- https://github.com/zonetti/zonoteProductThird Party Advisory
- https://medium.com/bugbountywriteup/remote-code-execution-through-cross-site-scrExploitThird Party Advisory
- https://www.electronjs.org/apps/zonoteProductThird Party Advisory
- https://github.com/hmartos/cve-2020-35717ExploitThird Party Advisory
- https://github.com/zonetti/zonoteProductThird Party Advisory
- https://medium.com/bugbountywriteup/remote-code-execution-through-cross-site-scrExploitThird Party Advisory
- https://www.electronjs.org/apps/zonoteProductThird Party Advisory
FAQ
What is CVE-2020-35717?
CVE-2020-35717 is a vulnerability with a CVSS score of 9.0 (CRITICAL). zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
How severe is CVE-2020-35717?
CVE-2020-35717 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-35717?
Check the references section above for vendor advisories and patch information. Affected products include: Electronjs Zonote.