mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 02:45:46 +02:00
704 B
704 B
CVE-2019-12137
Description
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
POC
Reference
- http://packetstormsecurity.com/files/153082/Typora-0.9.9.24.6-Directory-Traversal.html
- https://github.com/typora/typora-issues/issues/2505
Github
No PoCs found on GitHub currently.