A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 13 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Lollms lollms Web Ui | |
| CPEs | cpe:2.3:a:lollms:lollms_web_ui:-:*:*:*:*:*:*:* | |
| Vendors & Products | Lollms lollms Webui | Lollms lollms Web Ui | 
Mon, 19 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Lollms Lollms lollms Webui | |
| CPEs | cpe:2.3:a:lollms:lollms_webui:-:*:*:*:*:*:*:* | |
| Vendors & Products | Lollms Lollms lollms Webui | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-27T18:46:17.563Z
Updated: 2024-08-01T21:25:03.177Z
Reserved: 2024-06-12T20:05:07.801Z
Link: CVE-2024-5933
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T21:25:03.177Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-06-27T19:15:17.840
Modified: 2025-02-13T15:43:43.267
Link: CVE-2024-5933
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow