CVE-2020-18748: XSS
Published Aug 19, 2021
·Updated
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. This is a different vulnerability from CVE-2020-18221.
Affected Software
1 affected component
Typora typora=0.9.65
Event History
Aug 19, 2021
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Cross Site Scripting (XSS) vulnerability in Typora v0.9.65?
The vulnerability ID is CVE-2020-18748.
2
How can attackers exploit the Cross Site Scripting (XSS) vulnerability in Typora v0.9.65?
Attackers can exploit the vulnerability by executing arbitrary code via mathjax syntax in the mathematical formula blocks.
3
What is the severity level of the Cross Site Scripting (XSS) vulnerability in Typora v0.9.65?
The severity level is medium, with a CVSS score of 6.1.
4
How can I fix the Cross Site Scripting (XSS) vulnerability in Typora v0.9.65?
There is no official fix or patch available for this vulnerability. It is recommended to update to the latest version of Typora when it becomes available.
5
Where can I find more information about the Cross Site Scripting (XSS) vulnerability in Typora v0.9.65?
You can find more information about the vulnerability on the Typora GitHub page and the Typora-issues GitHub repository.