CVE-2024-53930

W

ikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.

Configurations

No configuration.

History

26 Nov 2024, 16:15

Type Values Removed Values Added
CWE CWE-79
Summary
  • (es) WikiDocs anterior a 1.0.65 permite el almacenamiento de XSS por parte de usuarios autenticados a través de datos que vienen después de $$\\, lo cual es manejado incorrectamente por un analizador KaTeX.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

25 Nov 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-25 03:15

Updated : 2024-11-26 16:15


NVD link : CVE-2024-53930

Mitre link : CVE-2024-53930

CVE.ORG link : CVE-2024-53930


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')