CVE-2024-11824
CVSS 3.0 Score 5.8 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 79
Summary
CVE-2024-11824 is a stored cross-site scripting (XSS) vulnerability affecting the latest version of langgenius/dify. This issue lies in the chat log functionality, where certain HTML tags such as <input> and <form> are permissible, enabling attackers to inject malicious HTML into the logs through prompts. When an administrator views the contaminated log, an attacker can potentially steal their credentials or access sensitive information. This vulnerability is resolved in version 0.12.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Dify