Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-39203 Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 06 Sep 2024 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Enchantedcode
Enchantedcode note Mark
CPEs cpe:2.3:a:enchantedcode:note_mark:*:*:*:*:*:*:*:*
Vendors & Products Enchantedcode
Enchantedcode note Mark

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-05T10:22:35.371Z

Reserved: 2024-07-22T13:57:37.137Z

Link: CVE-2024-41819

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:53.175Z

cve-icon NVD

Status : Modified

Published: 2024-07-29T16:15:05.797

Modified: 2024-11-21T09:33:08.247

Link: CVE-2024-41819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.