Vulnerability Details CVE-2019-12173
MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element. This is different from CVE-2019-12138.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.031
EPSS Ranking 86.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2019-12173
-
cpe:2.3:a:macdown_project:macdown:0.7.1