CVE-2022-40011
EUVD-2022-4333623.12.2022, 23:15
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| typora | typora | 𝑥 ≤ 1.3.8 |
𝑥
= Vulnerable software versions