A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms lollms Web Ui
|
|
| CPEs | cpe:2.3:a:lollms:lollms_web_ui:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms lollms Webui
|
Lollms lollms Web Ui
|
Mon, 19 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms
Lollms lollms Webui |
|
| CPEs | cpe:2.3:a:lollms:lollms_webui:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms
Lollms lollms Webui |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-27T18:46:17.563Z
Updated: 2024-08-01T21:25:03.177Z
Reserved: 2024-06-12T20:05:07.801Z
Link: CVE-2024-5933
Updated: 2024-08-01T21:25:03.177Z
Status : Analyzed
Published: 2024-06-27T19:15:17.840
Modified: 2025-02-13T15:43:43.267
Link: CVE-2024-5933
No data.
ReportizFlow