CVE-2023-44141
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 30, 2023
Updated: Nov 6, 2023
CWE ID 94
Summary
CVE-2023-44141 is a vulnerability affecting Inkdrop, a markdown editor, prior to version 5.6.0. An attacker can exploit this issue by creating a maliciously crafted markdown file and having a legitimate user open it. The vulnerability permits code injection, potentially leading to arbitrary code execution within the application. Successful exploitation grants the attacker extensive control over the editor and could result in data theft or system compromise. Users are advised to upgrade to the latest version of Inkdrop to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Inkdrop
Affected Vendors
- Inkdrop