PT-2024-37813 · Unknown · Open-Webui

Jaggar Henry

+1

·

Published

2024-08-07

·

Updated

2024-08-15

·

CVE-2024-6706

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Open WebUI version 0.1.105
Description The issue allows attackers to craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page. This enables attackers to inject malicious scripts.
Recommendations For Open WebUI version 0.1.105, patch immediately and validate user input to mitigate the risk.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6706
GHSA-5JP3-WP5V-5363

Affected Products

Open-Webui