A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser.
Metrics
Affected Vendors & Products
References
History
Mon, 19 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lollms
Lollms lollms Webui |
|
CPEs | cpe:2.3:a:lollms:lollms_webui:-:*:*:*:*:*:*:* | |
Vendors & Products |
Lollms
Lollms lollms Webui |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-27T18:46:17.563Z
Updated: 2024-08-01T21:25:03.177Z
Reserved: 2024-06-12T20:05:07.801Z
Link: CVE-2024-5933
Vulnrichment
Updated: 2024-08-01T21:25:03.177Z
NVD
Status : Modified
Published: 2024-06-27T19:15:17.840
Modified: 2024-11-21T09:48:36.263
Link: CVE-2024-5933
Redhat
No data.