CVE-2024-6986
CVSS 3.0 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-6986 is a newly identified Cross-site Scripting (XSS) vulnerability affecting the Settings page of the parisneo/lollms-webui version 9.8. The issue arises due to the misuse of the 'v-html' directive, which inserts the content of the 'full_template' variable directly into HTML code. By exploiting this flaw, attackers can inject malicious JavaScript code into the 'System Template' input field under main configurations, ultimately leading to unintended execution and potential data breaches. This vulnerability represents a significant security risk and requires immediate attention and patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.