CVE-2020-18221: XSS
Published May 26, 2021
·Updated
Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.
Affected Software
1 affected component
Typora typora<=0.9.65
Event History
May 26, 2021
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
Description
Frequently Asked Questions
1
What is CVE-2020-18221?
CVE-2020-18221 is a Cross Site Scripting (XSS) vulnerability in Typora v0.9.65 and earlier.
2
How does CVE-2020-18221 work?
CVE-2020-18221 allows remote attackers to execute arbitrary code by injecting commands during the rendering of a mathematical formula in Typora.
3
What is the severity of CVE-2020-18221?
The severity of CVE-2020-18221 is medium with a CVSS score of 6.1.
4
How can I check if I am affected by CVE-2020-18221?
If you are using Typora version 0.9.65 or earlier, you might be affected by CVE-2020-18221.
5
How do I fix CVE-2020-18221?
To fix CVE-2020-18221, update to the latest version of Typora.