CVE-2024-11850
CVSS 3.0 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-11850 is a newly discovered stored cross-site scripting (XSS) vulnerability affecting the latest version of langgenius/dify. This issue arises due to insufficient validation and sanitization of user input in the SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by inserting malicious SVG content, which can execute arbitrary JavaScript code when accessed by an admin. Successful exploitation of this flaw may result in credential theft. Users are urged to apply patches or updates as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.