CVE-2024-12871
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79
Summary
CVE-2024-12871 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting version 0.12.0 of infiniflow/ragflow. The issue enables attackers to upload malicious PDF files to the knowledge base, which, upon being viewed within Ragflow, executes the payload in the user's browser. The consequences of this vulnerability can be severe, potentially leading to session hijacking, data exfiltration, and unauthorized actions on behalf of the victim. This puts sensitive user data at risk and compromises the overall integrity of the application.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.