PT-2024-24235 · Tiagorlampert · Chaos

Published

2024-04-12

·

Updated

2025-08-27

·

CVE-2024-31839

CVSS v3.1
4.8
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

tiagorlampert CHAOS version 5.0.1

Description:

A Cross Site Scripting (XSS) vulnerability exists in tiagorlampert CHAOS. A remote attacker may be able to escalate privileges via the `sendCommandHandler` function in the `handler.go` component. A malicious actor may be able to extract a JWT (JSON Web Token) token via a malicious "/command" request.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-31839
GHSA-C5RV-HJJC-JV7M
GO-2024-2721

Affected Products

Chaos