Skip to content
Noroxi

boostnote records

2 published records for vendor boostnote.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 21

Bar: total · dark part: CISA KEV.

Attack profile

All records

2 records
  • static/main-preload.js in Boost Note through 0.22.0 allows remote command execution.

    CriticalCVSS 9.8No exploitEPSS 3%

    boostnote · boostnoteSep 17, 2021

  • Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.

    MediumCVSS 6.1No exploitEPSS 1%

    boostnote · boostnoteJul 8, 2018