An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the user's browser. This can lead to session hijacking, data exfiltration, or unauthorized actions performed on behalf of the victim, compromising sensitive user data and affecting the integrity of the entire application.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infiniflow
Infiniflow ragflow |
|
CPEs | cpe:2.3:a:infiniflow:ragflow:0.12.0:*:*:*:*:*:*:* | |
Vendors & Products |
Infiniflow
Infiniflow ragflow |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the user's browser. This can lead to session hijacking, data exfiltration, or unauthorized actions performed on behalf of the victim, compromising sensitive user data and affecting the integrity of the entire application. | |
Title | Stored Cross-site Scripting (XSS) in infiniflow/ragflow | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:07.129Z
Updated: 2025-03-20T13:35:32.904Z
Reserved: 2024-12-20T20:18:10.013Z
Link: CVE-2024-12871

Updated: 2025-03-20T13:35:22.798Z

Status : Analyzed
Published: 2025-03-20T10:15:31.340
Modified: 2025-04-01T20:34:33.523
Link: CVE-2024-12871

No data.