Skip to content

giovannipajeu1/CVE-2023-50643

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 

Repository files navigation

CVE-2023-50643

CVE-2023-50643

An issue in Evernote for MacOS v.10.68.2 allows a remote, attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components

There is a tool designed to automate the process of searching for vulnerabilities in electron: https://github.com/r3ggi/electroniz3r

image

With this tool, we can check if the App is Vulnerable:

image

After validation, we can inject our code, and get a shell

image

Enjoy Shell :)

image

This CVE was only discovered with the help of a great friend and researcher - https://github.com/louiselalanne/CVE-2023-49314

About

CVE-2023-50643

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published