CVE-2019-7295: XSS
Published Jan 31, 2019
·Updated
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
Affected Software
1 affected component
Typora typora<=0.9.63
Event History
Jan 31, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-7295?
CVE-2019-7295 is a vulnerability in Typora through 0.9.63 that allows for XSS (cross-site scripting) with resultant remote command execution during block rendering of a mathematical formula.
2
What is the severity of CVE-2019-7295?
CVE-2019-7295 has a severity rating of 6.1, which is considered medium.
3
How can this vulnerability be exploited?
This vulnerability can be exploited by injecting malicious code into a mathematical formula, leading to XSS and potential remote command execution.
4
Which software versions are affected by CVE-2019-7295?
Typora versions up to and including 0.9.63 are affected by CVE-2019-7295.
5
Is there a fix available for CVE-2019-7295?
Yes, updating to a version of Typora beyond 0.9.63 is recommended to mitigate the vulnerability.