CVE-2024-11824

CVSS 3.0 Score 5.8 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 79

Summary

CVE-2024-11824 is a stored cross-site scripting (XSS) vulnerability affecting the latest version of langgenius/dify. This issue lies in the chat log functionality, where certain HTML tags such as <input> and <form> are permissible, enabling attackers to inject malicious HTML into the logs through prompts. When an administrator views the contaminated log, an attacker can potentially steal their credentials or access sensitive information. This vulnerability is resolved in version 0.12.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share