CVE-2018-1999024: XSS
MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-1999024?
CVE-2018-1999024 is a Cross Site Scripting (XSS) vulnerability in MathJax version prior to version 2.7.4.
What is the severity of CVE-2018-1999024?
CVE-2018-1999024 has a severity rating of 5.4 (Medium).
How can the CVE-2018-1999024 vulnerability be exploited?
The CVE-2018-1999024 vulnerability can be exploited when a victim views a page where untrusted content is processed.
What is the recommended remedy for CVE-2018-1999024?
The recommended remedy for CVE-2018-1999024 is to update MathJax to version 2.7.4 or later.
Where can I find more information about CVE-2018-1999024?
You can find more information about CVE-2018-1999024 in the references provided: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-1999024), [GitHub](https://github.com/mathjax/MathJax/commit/a55da396c18cafb767a26aa9ad96f6f4199852f1) and [Blog](https://blog.bentkowski.info/2018/06/xss-in-google-colaboratory-csp-bypass.html).