Critical
CVSS 9.0
Overview
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code E...
zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).
This vulnerability is rated 🔴 CRITICAL.
Recommended actions: