CVE-2024-6986

CVSS 3.0 Score 5.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 79

Summary

CVE-2024-6986 is a newly identified Cross-site Scripting (XSS) vulnerability affecting the Settings page of the parisneo/lollms-webui version 9.8. The issue arises due to the misuse of the 'v-html' directive, which inserts the content of the 'full_template' variable directly into HTML code. By exploiting this flaw, attackers can inject malicious JavaScript code into the 'System Template' input field under main configurations, ultimately leading to unintended execution and potential data breaches. This vulnerability represents a significant security risk and requires immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share