Vulnerability Description
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inkdrop | Inkdrop | < 5.3.1 |
Related Weaknesses (CWE)
References
- https://docs.inkdrop.app/releases/5.3.1Release NotesVendor Advisory
- https://jvn.jp/en/jp/JVN29949691/index.htmlThird Party Advisory
- https://www.inkdrop.app/ProductVendor Advisory
- https://docs.inkdrop.app/releases/5.3.1Release NotesVendor Advisory
- https://jvn.jp/en/jp/JVN29949691/index.htmlThird Party Advisory
- https://www.inkdrop.app/ProductVendor Advisory
FAQ
What is CVE-2021-20745?
CVE-2021-20745 is a vulnerability with a CVSS score of 7.8 (HIGH). Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.
How severe is CVE-2021-20745?
CVE-2021-20745 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20745?
Check the references section above for vendor advisories and patch information. Affected products include: Inkdrop Inkdrop.