CVE-2019-7296: XSS
Published Jan 31, 2019
·Updated
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
Affected Software
1 affected component
Typora typora<=0.9.64
Event History
Jan 31, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-7296?
CVE-2019-7296 is a vulnerability in Typora version 0.9.64 that allows for XSS attacks and remote command execution when rendering inline mathematical formulas.
2
What is the severity of CVE-2019-7296?
The severity of CVE-2019-7296 is medium.
3
How does CVE-2019-7296 affect Typora?
CVE-2019-7296 affects Typora version 0.9.64, allowing for XSS attacks and remote command execution during the inline rendering of mathematical formulas.
4
How can I fix CVE-2019-7296?
To fix CVE-2019-7296, update your Typora installation to a version later than 0.9.64.
5
Where can I find more information about CVE-2019-7296?
You can find more information about CVE-2019-7296 at the following link: [https://github.com/typora/typora-issues/issues/2131](https://github.com/typora/typora-issues/issues/2131).