6.1 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
24 packages
- libmaxminddb
- phpExtensions.maxminddb
- python312Packages.xmind
- python313Packages.xmind
- dotnetPackages.MaxMindDb
- php81Extensions.maxminddb
- php82Extensions.maxminddb
- php83Extensions.maxminddb
- php84Extensions.maxminddb
- python312Packages.maxminddb
- python313Packages.maxminddb
- dotnetPackages.MaxMindGeoIP2
- perlPackages.MaxMindDBCommon
- perl540Packages.MaxMindDBReaderXS
- perl538Packages.MaxMindDBReaderXS
- perl540Packages.MaxMindDBWriter
- perl540Packages.MaxMindDBReader
- perl540Packages.MaxMindDBCommon
- perl538Packages.MaxMindDBWriter
- perl538Packages.MaxMindDBReader
- perl538Packages.MaxMindDBCommon
- perlPackages.MaxMindDBWriter
- perlPackages.MaxMindDBReader
- perlPackages.MaxMindDBReaderXS
- @LeSuisse dismissed
Xmind 2020 - Persistent Cross-Site Scripting
Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.
References
-
ExploitDB-49827 exploit
-
Official Xmind Product Homepage product
-
Proof of Concept Video exploit
-
Affected products
- ==2020
Matching in nixpkgs
pkgs.xmind
All-in-one thinking tool featuring mind mapping, AI generation, and real-time collaboration
-
nixos-unstable 25.07.03033-202507241842
- nixpkgs-unstable 25.07.03033-202507241842
- nixos-unstable-small 25.07.03033-202507241842
Ignored packages (24)
pkgs.libmaxminddb
C library for working with MaxMind geolocation DB files
pkgs.phpExtensions.maxminddb
C extension that is a drop-in replacement for MaxMind\Db\Reader
pkgs.python312Packages.xmind
Python module to create mindmaps
pkgs.python313Packages.xmind
Python module to create mindmaps
pkgs.dotnetPackages.MaxMindDb
None
pkgs.php81Extensions.maxminddb
C extension that is a drop-in replacement for MaxMind\Db\Reader
pkgs.php82Extensions.maxminddb
C extension that is a drop-in replacement for MaxMind\Db\Reader
pkgs.php83Extensions.maxminddb
C extension that is a drop-in replacement for MaxMind\Db\Reader
pkgs.php84Extensions.maxminddb
C extension that is a drop-in replacement for MaxMind\Db\Reader
pkgs.python312Packages.maxminddb
Reader for the MaxMind DB format
pkgs.python313Packages.maxminddb
Reader for the MaxMind DB format
pkgs.dotnetPackages.MaxMindGeoIP2
None
pkgs.perlPackages.MaxMindDBCommon
Code shared by the MaxMind DB reader and writer modules
pkgs.perlPackages.MaxMindDBReader
Read MaxMind DB files and look up IP addresses
pkgs.perlPackages.MaxMindDBWriter
Create MaxMind DB database files
pkgs.perlPackages.MaxMindDBReaderXS
Fast XS implementation of MaxMind DB reader
pkgs.perl538Packages.MaxMindDBCommon
Code shared by the MaxMind DB reader and writer modules
pkgs.perl538Packages.MaxMindDBReader
Read MaxMind DB files and look up IP addresses
pkgs.perl538Packages.MaxMindDBWriter
Create MaxMind DB database files
pkgs.perl540Packages.MaxMindDBCommon
Code shared by the MaxMind DB reader and writer modules
pkgs.perl540Packages.MaxMindDBReader
Read MaxMind DB files and look up IP addresses
pkgs.perl540Packages.MaxMindDBWriter
Create MaxMind DB database files
pkgs.perl538Packages.MaxMindDBReaderXS
Fast XS implementation of MaxMind DB reader
pkgs.perl540Packages.MaxMindDBReaderXS
Fast XS implementation of MaxMind DB reader
Package maintainers
-
@michalrus Michal Rus <m@michalrus.com>