Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Whoisoo6

#38126of 53,625
7.3Total CVSS
Vulnerabilities · 1
PT-2024-25191
7.3
2024-05-01
Typora · Typora · CVE-2024-33300
**Name of the Vulnerable Software and Affected Versions** Typora versions 1.0.0 through 1.7 **Description** The issue is related to a cross-site scripting (XSS) vulnerability in the Markdown editor, which allows attackers to execute arbitrary code by uploading Markdown files. **Recommendations** For versions 1.0.0 through 1.7, consider disabling the Markdown file upload feature until a patch is available. Restrict access to the Markdown editor to minimize the risk of exploitation. Avoid using the affected Markdown editor until the issue is resolved.