CVE-2024-9148

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Sep 30, 2024
CWE ID 79

Summary

CVE-2024-9148 is a newly disclosed vulnerability affecting Flowise, an open-source marketing automation tool. The issue lies in the Chat Embed component, version 1.x, which is prone to Stored Cross-Site Scripting (XSS) attacks. The root cause is the absence of proper input sanitization, enabling attackers to inject malicious scripts into the chat interface. Successful exploitation could lead to unauthorized access to user data, session hijacking, or other malicious activities. Users are recommended to upgrade to Flowise Chat Embed version 2.0.0 or later to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • FlowiseAI Flowise

Affected Vendors

  • FlowiseAI