CVE-2024-31783: XSS
Published Apr 16, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.
Affected Software
2 affected components
Typora typora<1.6.7
Typora typora<=1.6.7
Event History
Apr 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31783?
CVE-2024-31783 is classified as a high severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-31783?
To fix CVE-2024-31783, upgrade Typora to version 1.6.8 or later.
3
What types of attacks are possible with CVE-2024-31783?
CVE-2024-31783 enables local attackers to execute crafted scripts that can result in the exposure of sensitive information.
4
Which versions of Typora are affected by CVE-2024-31783?
CVE-2024-31783 affects Typora versions 1.6.7 and earlier.
5
What is the impact of CVE-2024-31783 on users?
The impact of CVE-2024-31783 on users includes the potential compromise of sensitive data stored in markdown files.