Headline
CVE-2022-28101: HTML Injection Leading to RCE in Turtl - Cyber Citadel
Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection.
Press Releases | 24 March 2022
HTML Injection vulnerability found in Turtl Notes, disclosed by Cyber Citadel researchers, could affect iOS and Android users.
Cyber Citadel’s Lead Security Researcher Rafay Baloch and Security Researcher Muhammad Samak disclosed an HTML Injection vulnerability found in the Turtl Notes application, which could lead to a potential RCE and NTLMv2 hash disclosure via abusing the arbitrary URI schemes.
Turtl Notes user interface
Turtl Notes
Turtl Notes is a cross-platform application that focuses on note-taking collaboration. The online service provides users with a notebook sharing platform that allows notes to be organised easily, synchronised across devices, shared with other Turtl users and shared via email. The application has been downloaded 10,000+ times on Google Play and an unknown number of times from the Turtl’s website for Windows, OSX, Linux, Android and iOS.
While Turtl encrypts user data, with an impressive 2,048-bit key encryption system, and boasts the implementation of high-grade firewalls, that protect from DDoS attacks, the HTML Injection vulnerability, found by Rafay Baloch and Muhammad Samak, has exposed a critical flaw in Turtl’s software.
Turtl remote code execution POC
Evidence of Turtle RCE vulnerability
Evidence of Turtle RCE vulnerability
Response from Vendors
Vendor
Service
Version
Platform
Reported Date
Fixed
CVE
Turtl
Turtl Notes
0.7.2.6
Windows, Mac, Linux, Android
11/12/2021
N/A
Processing