Cross Site Scripting (XSS) Vulnerability in Leanote 2.7.0 Markdown Note Type

Cross Site Scripting (XSS) Vulnerability in Leanote 2.7.0 Markdown Note Type

CVE-2021-43721 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>

Learn more about our Web Application Penetration Testing UK.