We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-9311

Cross-Site Request Forgery to XSS in haotian-liu/llava



Description

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of the victim's browser by visiting the crafted file URL. This can lead to theft of sensitive information, session hijacking, or other actions compromising the security and privacy of the victim.

Reserved 2024-09-27 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Any version
affected

References

huntr.com/bounties/15b18b85-5a6b-43e7-bc65-6b4772871e98

cve.org (CVE-2024-9311)

nvd.nist.gov (CVE-2024-9311)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-9311

Support options

Helpdesk Chat, Email, Knowledgebase