CVE-2024-1602

Source
https://cve.org/CVERecord?id=CVE-2024-1602
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1602.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-1602
Published
2024-04-10T17:08:02.423Z
Modified
2026-08-12T03:51:16.284642087Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Stored XSS leading to RCE in parisneo/lollms-webui
Details

parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the /execute_code endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "@huntr_ai",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1602.json"
}
References

Affected packages

Git / github.com/parisneo/lollms-webui

Affected ranges

Type
GIT
Repo
https://github.com/parisneo/lollms-webui
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:lollms:lollms_web_ui:9.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "9.0"
        },
        {
            "last_affected": "9.0"
        }
    ]
}

Affected versions

9.*
9.0
v9.*
v9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1602.json"