Vulnerability Description
Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enchantedcode | Note Mark | < 0.13.1 |
Related Weaknesses (CWE)
References
- https://github.com/enchant97/note-mark/commit/a0997facb82f85bfb8c0d497606d89e7d1Patch
- https://github.com/enchant97/note-mark/security/advisories/GHSA-rm48-9mqf-8jc3ExploitVendor Advisory
- https://github.com/enchant97/note-mark/commit/a0997facb82f85bfb8c0d497606d89e7d1Patch
- https://github.com/enchant97/note-mark/security/advisories/GHSA-rm48-9mqf-8jc3ExploitVendor Advisory
FAQ
What is CVE-2024-41819?
CVE-2024-41819 is a vulnerability with a CVSS score of 8.7 (HIGH). Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the UR...
How severe is CVE-2024-41819?
CVE-2024-41819 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41819?
Check the references section above for vendor advisories and patch information. Affected products include: Enchantedcode Note Mark.