CVE-2021-41392
17.09.2021, 22:15
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
Vendor | Product | Version |
---|---|---|
boostnote | boostnote | 𝑥 ≤ 0.22.0 |
𝑥
= Vulnerable software versions