HTTP: Joplin MdToHtml Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against Joplin MdToHtml. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via improper santization.

Affected Products

Joplin_project joplin

Short Name
HTTP:XSS:JOPLIN-MD-TO-HTML
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2022-45598 Cross-Site Joplin MdToHtml Scripting
Release Date
03/28/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3583
False Positive
Rarely
Vendors

Joplin_project

Found a potential security threat?