CVE-2019-6803

typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
typoratypora
0.8.1:alpha
typoratypora
0.8.2:alpha
typoratypora
0.8.5:alpha
typoratypora
0.8.6:alpha
typoratypora
0.8.7:alpha
typoratypora
0.8.8:beta
typoratypora
0.8.9:beta
typoratypora
0.9.0:beta
typoratypora
0.9.1:beta
typoratypora
0.9.2:beta
typoratypora
0.9.3:beta
typoratypora
0.9.4:beta
typoratypora
0.9.4.5:beta
typoratypora
0.9.5:beta
typoratypora
0.9.5.6:beta
typoratypora
0.9.5.7:beta
typoratypora
0.9.6:beta
typoratypora
0.9.6.1:beta
typoratypora
0.9.6.8:beta
typoratypora
0.9.7:beta
typoratypora
0.9.7.4:beta
typoratypora
0.9.7.5:beta
typoratypora
0.9.7.8:beta
typoratypora
0.9.7.9:beta
typoratypora
0.9.8:beta
typoratypora
0.9.8.1:beta
typoratypora
0.9.8.5:beta
typoratypora
0.9.8.6:beta
typoratypora
0.9.8.7:beta
typoratypora
0.9.8.7.2:beta
typoratypora
0.9.8.8:beta
typoratypora
0.9.9.0:beta
typoratypora
0.9.9.1:beta
typoratypora
0.9.9.2:beta
typoratypora
0.9.9.2.1:beta
typoratypora
0.9.9.2.5:beta
typoratypora
0.9.9.3:beta
typoratypora
0.9.9.4:beta
typoratypora
0.9.9.4.4:beta
typoratypora
0.9.9.5:beta
typoratypora
0.9.9.5.1
typoratypora
0.9.9.6:beta
typoratypora
0.9.9.6.2:beta
typoratypora
0.9.9.6.4:beta
typoratypora
0.9.9.7:beta
typoratypora
0.9.9.7.1:beta
typoratypora
0.9.9.7.6:beta
typoratypora
0.9.9.7.8:beta
typoratypora
0.9.9.8:beta
typoratypora
0.9.9.8.2:beta
typoratypora
0.9.9.8.4:beta
typoratypora
0.9.9.8.5:beta
typoratypora
0.9.9.8.8:beta
typoratypora
0.9.9.8.9:beta
typoratypora
0.9.9.9.0:beta
typoratypora
0.9.9.9.2:beta
typoratypora
0.9.9.9.3:beta
typoratypora
0.9.9.9.4:beta
typoratypora
0.9.9.9.4.2:beta
typoratypora
0.9.9.10:beta
typoratypora
0.9.9.10.1:beta
typoratypora
0.9.9.10.2:beta
typoratypora
0.9.9.10.3:beta
typoratypora
0.9.9.10.4:beta
typoratypora
0.9.9.10.6:beta
typoratypora
0.9.9.10.7:beta
typoratypora
0.9.9.10.8:beta
typoratypora
0.9.9.10.9:beta
typoratypora
0.9.9.11:beta
typoratypora
0.9.9.11.2:beta
typoratypora
0.9.9.12:beta
typoratypora
0.9.9.12.4:beta
typoratypora
0.9.9.12.5
typoratypora
0.9.9.13:beta
typoratypora
0.9.9.13.6:beta
typoratypora
0.9.9.14:beta
typoratypora
0.9.9.15:beta
typoratypora
0.9.9.15.2:beta
typoratypora
0.9.9.15.3:beta
typoratypora
0.9.9.16:beta
typoratypora
0.9.9.16.1:beta
typoratypora
0.9.9.16.2:beta
typoratypora
0.9.9.17:beta
typoratypora
0.9.9.17.4:beta
typoratypora
0.9.9.17.5:beta
typoratypora
0.9.9.18:beta
typoratypora
0.9.9.18.1:beta
typoratypora
0.9.9.19:beta
typoratypora
0.9.9.19.3:beta
typoratypora
0.9.9.19.4:beta
typoratypora
0.9.9.20:beta
typoratypora
0.9.9.20.1:beta
typoratypora
0.9.9.20.2:beta
typoratypora
0.9.9.20.3:beta
𝑥
= Vulnerable software versions