CVE-2024-9148
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-9148 is a newly disclosed vulnerability affecting Flowise, an open-source marketing automation tool. The issue lies in the Chat Embed component, version 1.x, which is prone to Stored Cross-Site Scripting (XSS) attacks. The root cause is the absence of proper input sanitization, enabling attackers to inject malicious scripts into the chat interface. Successful exploitation could lead to unauthorized access to user data, session hijacking, or other malicious activities. Users are recommended to upgrade to Flowise Chat Embed version 2.0.0 or later to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FlowiseAI Flowise
Affected Vendors
- FlowiseAI