Hacking Electron Apps (CVE-2020-35717)

In this blog, we’ll discuss how the zonote Electron app can be exploited via the infamous CVE-2020-35717 vulnerability. The CVE reads zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because node Integration in webPreferences is true). Electron Applications  Electron is a well-known open-source library that is used by well-established firms including...