CVE-2021-41392

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
17/09/2021
Last modified:
29/09/2021

Description

static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:boostnote:boostnote:*:*:*:*:*:*:*:* 0.22.0 (including)


References to Advisories, Solutions, and Tools