Cross-Site Scripting Vulnerability in Typora by Typora
CVE-2019-6803

6.1MEDIUM

Key Information:

Vendor

Typora

Status
Vendor
CVE Published:
25 January 2019

What is CVE-2019-6803?

Typora, a popular markdown editor, is susceptible to a cross-site scripting (XSS) vulnerability. This flaw allows attackers to execute remote commands through malicious scripts inserted via the left outline bar. The vulnerability affects all versions leading up to 0.9.9.20.3 beta, highlighting the necessity for users to update their software to safeguard their systems against potential threats.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.