PT-2024-37248 · Parisneo · Lollms-Webui

Published

2024-06-27

·

Updated

2024-08-19

·

CVE-2024-5933

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: parisneo/lollms-webui version latest
Description: A Cross-site Scripting (XSS) issue exists in the chat functionality, allowing an attacker to inject malicious scripts via chat messages. These scripts are then executed in the context of the user's browser.
Recommendations: For the latest version, consider disabling the chat functionality until a patch is available to prevent exploitation of this issue. Restrict access to the chat module to minimize the risk of malicious script injection. Avoid using the chat feature in the affected version until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5933

Affected Products

Lollms-Webui