CVE-2022-40011
23.12.2022, 23:15
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
| Vendor | Product | Version |
|---|---|---|
| typora | typora | 𝑥 ≤ 1.38 |
𝑥
= Vulnerable software versions