CVE-2024-1602

Source
https://cve.org/CVERecord?id=CVE-2024-1602
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1602.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-1602
Published
2024-04-10T17:08:02.423Z
Modified
2026-07-15T01:48:49.909223602Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Stored XSS leading to RCE in parisneo/lollms-webui
Details

parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the /execute_code endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "@huntr_ai",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1602.json"
}
References

Affected packages

Git / github.com/parisneo/lollms-webui

Affected ranges

Type
GIT
Repo
https://github.com/parisneo/lollms-webui
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "9.0"
        },
        {
            "last_affected": "9.0"
        }
    ],
    "cpe": "cpe:2.3:a:lollms:lollms_web_ui:9.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

9.*
9.0
v9.*
v9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1602.json"