CVE-2024-33300: XSS
Published May 1, 2024
·Updated
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.
Affected Software
2 affected components
Typora typora>=1.0.0<=1.7
Typora typora>=1.0.0<=1.7.0
Event History
May 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33300?
CVE-2024-33300 has a high severity due to the potential for arbitrary code execution via cross-site scripting.
2
How do I fix CVE-2024-33300?
To fix CVE-2024-33300, users should upgrade Typora to version 1.8 or later.
3
What kind of attack is possible with CVE-2024-33300?
CVE-2024-33300 allows attackers to execute arbitrary code by exploiting a cross-site scripting vulnerability through malicious Markdown files.
4
Which versions of Typora are affected by CVE-2024-33300?
Typora versions from 1.0.0 through 1.7 are affected by CVE-2024-33300.
5
Can CVE-2024-33300 be exploited remotely?
Yes, CVE-2024-33300 can be exploited remotely if the user opens a malicious Markdown file.