CVE-2019-6803

UnknownEPSS 1.87%

Last modified

CVE-2019-6803 is a vulnerability of currently unknown severity. typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.. EPSS estimates a 1.87% chance of exploitation in the next 30 days.

Description

typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.

Metrics

EPSS Probability
1.87%

76.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
TyporaTypora0.8.1Alpha
TyporaTypora0.8.2Alpha
TyporaTypora0.8.5Alpha
TyporaTypora0.8.6Alpha
TyporaTypora0.8.7Alpha
TyporaTypora0.8.8Beta
TyporaTypora0.8.9Beta
TyporaTypora0.9.0Beta
TyporaTypora0.9.1Beta
TyporaTypora0.9.2Beta
TyporaTypora0.9.3Beta
TyporaTypora0.9.4Beta
TyporaTypora0.9.4.5Beta
TyporaTypora0.9.5Beta
TyporaTypora0.9.5.6Beta
TyporaTypora0.9.5.7Beta
TyporaTypora0.9.6Beta
TyporaTypora0.9.6.1Beta
TyporaTypora0.9.6.8Beta
TyporaTypora0.9.7Beta
TyporaTypora0.9.7.4Beta
TyporaTypora0.9.7.5Beta
TyporaTypora0.9.7.8Beta
TyporaTypora0.9.7.9Beta
TyporaTypora0.9.8Beta
TyporaTypora0.9.8.1Beta
TyporaTypora0.9.8.5Beta
TyporaTypora0.9.8.6Beta
TyporaTypora0.9.8.7Beta
TyporaTypora0.9.8.7.2Beta
TyporaTypora0.9.8.8Beta
TyporaTypora0.9.9.0Beta
TyporaTypora0.9.9.1Beta
TyporaTypora0.9.9.2Beta
TyporaTypora0.9.9.2.1Beta
TyporaTypora0.9.9.2.5Beta
TyporaTypora0.9.9.3Beta
TyporaTypora0.9.9.4Beta
TyporaTypora0.9.9.4.4Beta
TyporaTypora0.9.9.5Beta
TyporaTypora0.9.9.5.1
TyporaTypora0.9.9.6Beta
TyporaTypora0.9.9.6.2Beta
TyporaTypora0.9.9.6.4Beta
TyporaTypora0.9.9.7Beta
TyporaTypora0.9.9.7.1Beta
TyporaTypora0.9.9.7.6Beta
TyporaTypora0.9.9.7.8Beta
TyporaTypora0.9.9.8Beta
TyporaTypora0.9.9.8.2Beta

Showing 50 of 94 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6803?
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
How severe is CVE-2019-6803?
Severity scoring for CVE-2019-6803 is pending analysis. The EPSS model estimates a 1.87% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6803?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6803?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST