Cross Site Scripting (XSS) Vulnerability in Leanote 2.7.0 Markdown Note Type
CVE-2021-43721 · MEDIUM Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x onerror=(function(){require('child_process').exec('calc');})();>
Learn more about our Web Application Penetration Testing UK.