S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2290 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in zadam/trilium affects v. prior to 0.52.4, 0.53.1-beta.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2290
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
zadam/triliumby zadam
AFFECTED< 0.53.1-betaSAFE ✓≥ 0.53.1-beta
Updated Aug 22, 2026View on NVD →
Detail

The zadam/trilium is an open-source note-taking tool designed for individuals, teams, and organizations. Featuring advanced features like cross-platform support, powerful text search, note tags, customizable note types, and tree hierarchy, zadam/trilium is an all-in-one solution for professionals who want to keep their work organized and accessible at all times. 

However, the CVE-2022-2290 vulnerability detected in this product poses a significant threat to users. This vulnerability is classified as a cross-site scripting (XSS) vulnerability, which allows attackers to inject malicious code into a user's browser session. XSS vulnerabilities are particularly dangerous because they can be used to steal user data, hijack user accounts, and compromise sensitive systems. 

When exploited, this vulnerability can lead to data breaches, identity theft, financial fraud, and more. Hackers can use this vulnerability to inject malicious scripts into a user's browser session, allowing them to steal user input, manipulate page content, and redirect users to malicious websites without their consent. With the potential damage that can be caused, it is vital that users take the necessary precautions to protect themselves against this vulnerability. 

It's important to remember that even with these precautions, no system can be 100% secure. That's where platforms like s4e.io come in. With its pro features, users can easily and quickly learn about vulnerabilities in their digital assets and stay up to date on the latest threats. So, don't hesitate to join the platform to keep yourself informed and protected.

 

REFERENCES

Solution Advice

So what can be done to protect yourself from the impacts of this vulnerability? Here are some precautions to consider:

  • Keep your software up to date: Make sure that you are using the latest version of zadam/trilium and that you regularly check for any updates.
  • Turn off inline CSS and Javascript: This will help reduce the risk of XSS vulnerabilities being exploited as it will prevent attackers from injecting malicious code into your browser.
  • Use security-focused browser extensions: Add-ons like NoScript and uBlock Origin can help block unwanted scripts and track third-party domains that may pose a threat.
  • Be cautious of opening links: Exercise caution when opening links, especially those from unknown sources. URLs may appear innocent at first, but the destination could lead you to a site that has been manipulated by an attacker.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-2290 scanner - Cross-Site Scripting (XSS) vulnerability in zadam/trilium | S4E