A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47062 | A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms lollms Web Ui
|
|
| CPEs | cpe:2.3:a:lollms:lollms_web_ui:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms lollms Webui
|
Lollms lollms Web Ui
|
Mon, 19 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms
Lollms lollms Webui |
|
| CPEs | cpe:2.3:a:lollms:lollms_webui:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms
Lollms lollms Webui |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T21:25:03.177Z
Reserved: 2024-06-12T20:05:07.801Z
Link: CVE-2024-5933
Updated: 2024-08-01T21:25:03.177Z
Status : Analyzed
Published: 2024-06-27T19:15:17.840
Modified: 2025-02-13T15:43:43.267
Link: CVE-2024-5933
No data.
OpenCVE Enrichment
No data.
EUVD