PT-2023-16680 · Typora · Typora

·

CVE-2023-1003

·

Published

2023-02-24

·

Updated

2024-05-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Typora versions 1.5.5 and earlier
Description A critical issue was found in the WSH JScript Handler component, leading to code injection. The manipulation requires a local attack approach. The issue has been publicly disclosed and may be exploited.
Recommendations For versions 1.5.5 and earlier, upgrade to version 1.5.8 to address this issue. As a temporary workaround, consider restricting access to the WSH JScript Handler component until the update is applied.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-1003

Affected Products

Typora