Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

U2400

#43150of 53,625
6.1Total CVSS
Vulnerabilities · 1
PT-2021-10234
6.1
2021-08-19
Typora · Typora · CVE-2020-18748
Name of the Vulnerable Software and Affected Versions: Typora version 0.9.65 Description: The issue is related to Cross Site Scripting (XSS) that allows attackers to execute arbitrary code via mathjax syntax. This is due to a mathjax configuration error in the mathematical formula blocks. Recommendations: For version 0.9.65, consider disabling the mathjax syntax in mathematical formula blocks as a temporary workaround until a patch is available. Restrict access to mathematical formula blocks to minimize the risk of exploitation.