Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2020-35717 — Proof-of-concept exploit for CVE-2020-35717 demonstrating XSS leading to remote code execution in zonote via crafted note import. | Kitploit
Tools/GitHubGitHub/hmartos/cve-2020-35717
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & Education
GitHubhmartos/cve-2020-35717

cve-2020-35717

Proof-of-concept exploit for CVE-2020-35717 demonstrating XSS leading to remote code execution in zonote via crafted note import.

View Repository
135 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2020–35717

zonote allows XSS via crafted note, with resultant Remote Code Execution (because Node.js integration is enabled).

Steps to exploit the vulnerability

  • Download any zonote affected version
  • Open zonote app
  • Import xss-rce.znt in zonote via Menu > Open
  • Hover over the different links in imported notes

Disclosure Timeline

  • 2020-12-26 Issue discovered and contact with the owner
  • 2020-12-26 Owner express his intention of not maintaining the repository nor fixing the vulnerability
  • 2021-01-01 Public disclosure of the vulnerability
Download Tool