CVE Database · CVE-2023-27035
CVSS v3.1
6.5
EPSS
1.84%
Published
May 1, 2023
Modified
Jan 30, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (6)