Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-10249 Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:15:58.909Z

Reserved: 2018-10-19T00:00:00

Link: CVE-2018-18524

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-13T14:29:00.817

Modified: 2024-11-21T03:56:05.847

Link: CVE-2018-18524

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.