The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
References
Link | Resource |
---|---|
https://github.com/laurent22/joplin/commit/19b45de2981c09f6f387498ef96d32b4811eba5e | Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-JOPLIN-1325537 | Patch Third Party Advisory |
Configurations
Information
Published : 2021-08-24 01:15
Updated : 2021-08-30 18:48
NVD link : CVE-2021-23431
Mitre link : CVE-2021-23431
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
joplinapp
- joplin