CVE-2024-41481
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Aug 12, 2024
Updated: Aug 13, 2024
CWE ID 79
Summary
CVE-2024-41481 is a newly disclosed cross-site scripting (XSS) vulnerability affecting Typora Markdown editor before version 1.9.3. This issue resides within the Mermaid component, which can be exploited by attackers to inject malicious scripts into web pages viewed by other users. Successful exploitation of this vulnerability could lead to unauthorized data access or theft, session hijacking, or other malicious activities. Users are strongly advised to upgrade to the latest version of Typora to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Typora