A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser.
History

Mon, 19 Aug 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Lollms
Lollms lollms Webui
CPEs cpe:2.3:a:lollms:lollms_webui:-:*:*:*:*:*:*:*
Vendors & Products Lollms
Lollms lollms Webui
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-27T18:46:17.563Z

Updated: 2024-08-01T21:25:03.177Z

Reserved: 2024-06-12T20:05:07.801Z

Link: CVE-2024-5933

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.177Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-27T19:15:17.840

Modified: 2024-08-19T21:07:56.627

Link: CVE-2024-5933

cve-icon Redhat

No data.