We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6986

Cross-site Scripting (XSS) in parisneo/lollms-webui



Description

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations.

Reserved 2024-07-22 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 5.5CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Any version
affected

References

huntr.com/bounties/83e9bde1-40b2-49e9-be1c-bc1498eb8ebd

cve.org (CVE-2024-6986)

nvd.nist.gov (CVE-2024-6986)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-6986

Support options

Helpdesk Chat, Email, Knowledgebase