PT-2024-37248 · Parisneo · Lollms-Webui
Published
2024-06-27
·
Updated
2024-08-19
·
CVE-2024-5933
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
parisneo/lollms-webui version latest
Description:
A Cross-site Scripting (XSS) issue exists in the chat functionality, allowing an attacker to inject malicious scripts via chat messages. These scripts are then executed in the context of the user's browser.
Recommendations:
For the latest version, consider disabling the chat functionality until a patch is available to prevent exploitation of this issue. Restrict access to the chat module to minimize the risk of malicious script injection. Avoid using the chat feature in the affected version until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms-Webui