PT-2024-37813 · Unknown · Open-Webui
Jaggar Henry
+1
·
Published
2024-08-07
·
Updated
2024-08-15
·
CVE-2024-6706
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Open WebUI version 0.1.105
Description
The issue allows attackers to craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page. This enables attackers to inject malicious scripts.
Recommendations
For Open WebUI version 0.1.105, patch immediately and validate user input to mitigate the risk.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Webui