CVE-2018-18524
UnknownEPSS 1.92%
Last modified
CVE-2018-18524 is a vulnerability of currently unknown severity. Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. EPSS estimates a 1.92% chance of exploitation in the next 30 days.
Description
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Evernote | Evernote | 6.15 |
References
- https://evernote.com/intl/en/security/updatesVendor Advisory
- https://paper.seebug.org/737/Exploit, Third Party Advisory
- https://evernote.com/intl/en/security/updatesVendor Advisory
- https://paper.seebug.org/737/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18524?
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
How severe is CVE-2018-18524?
Severity scoring for CVE-2018-18524 is pending analysis. The EPSS model estimates a 1.92% probability of exploitation in the next 30 days.
How do I fix CVE-2018-18524?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18515Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-18516Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-18517Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x b…
- CVE-2018-18519BestXsoftware Best Free Keylogger before 6.0.0 allows local …
- CVE-2018-18520An Invalid Memory Address Dereference exists in the function…6.5
- CVE-2018-18521Divide-by-zero vulnerabilities in the function arlib_add_sym…5.5
- CVE-2018-18527OwnTicket 2018-05-23 allows SQL Injection via the showTicket…
- CVE-2018-18529ThinkPHP 3.2.4 has SQL Injection via the count parameter bec…
- CVE-2018-1853IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1…6.1
- CVE-2018-18530ThinkPHP 5.1.25 has SQL Injection via the count parameter be…
- CVE-2018-18531text/impl/DefaultTextCreator.java, text/impl/ChineseTextProd…
- CVE-2018-18535The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and …
Are you affected by CVE-2018-18524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
