Vulnerabilities
Vulnerable Software
Boostnote:  >> Boostnote  Security Vulnerabilities
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
CVSS Score
9.8
EPSS Score
0.071
Published
2021-09-17
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-07-08


Contact Us

Shodan ® - All rights reserved