Description
Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.
Published: 2024-07-29
Score: 8.7 High
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-39203 Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.
History

Fri, 06 Sep 2024 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Enchantedcode
Enchantedcode note Mark
CPEs cpe:2.3:a:enchantedcode:note_mark:*:*:*:*:*:*:*:*
Vendors & Products Enchantedcode
Enchantedcode note Mark

Subscriptions

Enchantedcode Note Mark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-05T10:22:35.371Z

Reserved: 2024-07-22T13:57:37.137Z

Link: CVE-2024-41819

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:53.175Z

cve-icon NVD

Status : Modified

Published: 2024-07-29T16:15:05.797

Modified: 2024-11-21T09:33:08.247

Link: CVE-2024-41819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses