CVE-2022-28101

Turtlapp Turtle Note v0.7.2.6 does not filter the tag during markdown parsing, allowing attackers to execute HTML injection.
References
Link Resource
https://www.cybercitadel.com/html-injection-turtl/ Exploit Third Party Advisory
https://github.com/turtl/tracker/issues/404 Exploit Issue Tracking
Configurations

Configuration 1

cpe:2.3:a:lyonbros:turtl:0.7.2.6:*:*:*:-:android:*:*
cpe:2.3:a:lyonbros:turtl:0.7.2.6:*:*:*:-:ios:*:*

Information

Published : 2022-04-28 02:15

Updated : 2022-05-06 04:58


NVD link : CVE-2022-28101

Mitre link : CVE-2022-28101

Products Affected
No products.
CWE