WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-11-25 03:15
Updated : 2026-06-17 08:09
NVD link : CVE-2024-53930
Mitre link : CVE-2024-53930
CVE.ORG link : CVE-2024-53930
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
