Code execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-10038 | Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.ap Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file. NVD description · AI analysis pending | 7.8 | 1% |
| — |
Full article139 words · extracted from securityaffairs.com · click to collapse

A local file path traversal issue exists in Evernote 7.9 for macOS which allows an attacker to execute arbitrary programs.
Technical observation:
A crafted URI can be used in a note to perform this attack using file:/// as an argument or by traversing to any directory like
(../../../../something.app).
Since Evernote also has a feature of sharing notes, in such a case an attacker could leverage this vulnerability and send crafted notes (.enex) to the victim to perform further attacks.
Patch:
A patch for this issue was released in Evernote 7.10 Beta 1 and 7.9.1 GA for macOS [MACOSNOTE-28840]. CVE-2019-10038 was assigned to this issue.
About the Author: Security Researcher Dhiraj Mishra (@mishradhiraj_)
Original post at:
https://www.inputzero.io/2019/04/evernote-cve-2019-10038.html
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Evernote, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/84037/hacking/local-file-path-traversal-evernote.html