CVE-2024-5125

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 434

Summary

CVE-2024-5125: parisneo's lollms-webui version 9.6 is vulnerable to both Cross-Site Scripting (XSS) and Open Redirect attacks. The former allows malicious JavaScript code to be embedded within SVG files, executing upon rendering, potentially leading to credential theft and data access. The latter stems from insufficient URL validation in SVG files, enabling redirection to malicious websites, exposing users to phishing attacks, malware distribution, and reputation damage. These vulnerabilities are found in the application's functionality for sending files to the AI module.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share