Evernote uxss漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# Evernote: Universal-XSS, theft of all cookies from all sites, and more Oversecured is a vulnerability analyzer for Android mobile apps. We frequently scan various popular apps to help secure as many users as possible against potential attacks that could lead to the theft of their personal data. One of the hundreds of popular apps in which we have discovered vulnerabilities was Evernote. ## Summary Oversecured found dangerous vulnerabilities in the Evernote app for Android, which could have allowed access to user accounts to be intercepted by a hostile app installed on the same device. Some time ago, we decided to scan the app a€” and we discovered six vulnerabilities. They included the potential for Universal-XSS (execution of arbitrary JavaScript code on an arbitrary domain), theft of cookies from all sites, rewriting of arbitrary files, and automatic activation of the microphone to eavesdrop on the user. Evernote fixed these issues as of release 8.12.2, released October 2019....

0%
暂无可用Exp或PoC
当前有0条受影响产品信息