Impact
A specially crafted ZIP file can include parent-directory traversal segments. An authenticated user who imports a ZIP vault can write files outside their own vault, including into other users’ vaults, overwriting existing files. If a disguised SVG file is placed in another user’s vault, opening that vault can trigger stored cross‑site scripting. The vulnerability therefore enables both data tampering and XSS, potentially compromising the confidentiality and integrity of other users’ data as well as inducing malicious code execution in victims’ browsers. The likely attack vector is an authenticated user uploading a malicious ZIP file through the app’s import feature. The description does not explicitly mention the exact path of exploitation, so this inference is drawn from the stated behaviour of the import routine. Affected systems are instances of Many Notes developed by brufdev. Prior to version 0.16.0 any user possessing the import privilege could exercise this capability, whereas the issue is fixed starting with 0.16.0.
Affected Systems
The vulnerability applies to all installations of Many Notes produced by brufdev. Versions earlier than 0.16.0 are affected; 0.16.0 and later are considered fixed.
Risk and Exploitability
The CVSS score of 9.6 assigns a high severity, reflecting the ability to write arbitrary files and trigger XSS. The EPSS score being less than 1% suggests that, as of the latest data, the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with import rights; no additional privileged conditions are described. The combination of high impact and low occurrence probability frames a scenario where organizations should still prioritize to eliminate the potential for user‑to‑user data poisoning and cross‑site scripting.
OpenCVE Enrichment