CVE-2024-12871

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2024-12871 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting version 0.12.0 of infiniflow/ragflow. The issue enables attackers to upload malicious PDF files to the knowledge base, which, upon being viewed within Ragflow, executes the payload in the user's browser. The consequences of this vulnerability can be severe, potentially leading to session hijacking, data exfiltration, and unauthorized actions on behalf of the victim. This puts sensitive user data at risk and compromises the overall integrity of the application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share