Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
CVE-2020-9038
See a problem?
Please try reporting it
to the source
first.
Source
https://cve.org/CVERecord?id=CVE-2020-9038
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9038.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-9038
Aliases
GHSA-6r7x-hc8m-985r
Published
2020-02-17T16:15:28Z
Modified
2026-05-17T11:55:02Z
Severity
5.4 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
References
https://github.com/laurent22/joplin/commit/3db47b575b9cb0a765da3d283baa2c065df0d0bc
https://github.com/laurent22/joplin/compare/clipper-1.0.19...clipper-1.0.20
http://packetstormsecurity.com/files/156582/Joplin-Desktop-1.0.184-Cross-Site-Scripting.html
Affected packages
CVE-2020-9038 - OSV