Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-12137. PoCs published by Dhiraj Mishra.
AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in Typora 0.9.9.24.6 on macOS via crafted URIs in shared notes, allowing arbitrary program execution. The PoC demonstrates how an attacker can use file:/// or ../ sequences to traverse directories and execute applications like Calculator.app.
Description
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
Exploits (1)
This exploit leverages a directory traversal vulnerability in Typora 0.9.9.24.6 on macOS via crafted URIs in shared notes, allowing arbitrary program execution. The PoC demonstrates how an attacker can use file:/// or ../ sequences to traverse directories and execute applications like Calculator.app.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H