CVE-2024-53930 Information

Description

WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\ which is mishandled by a KaTeX parser.

Reference

https://github.com/Zavy86/WikiDocs/commit/aa264bd046a254522da67600be73791bd4e5dafc https://github.com/Zavy86/WikiDocs/compare/1.0.64…1.0.65 https://github.com/Zavy86/WikiDocs/issues/211 https://github.com/Zavy86/WikiDocs/pull/213 https://github.com/Zavy86/WikiDocs/releases/tag/1.0.65 https://www.xbow.com

Share on: