CVE Feed

    Dashboard / CVE / CVE-2024-0435

    CVE-2024-0435

    User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given the minimum requirement for a user to send a chat is to be given access to a workspace via an admin the risk is low. Additionally, the location in which the XSS renders is only limited to the user who submits the XSS. Ultimately, this attack is limited to the user attacking themselves. There is no anonymous chat submission unless the user does not take the minimum steps required to protect their instance.

    Published:Feb 25, 2024
    Last Modified:Feb 25, 2025
    EPS:Feb 25, 2024
    EPSS Score:0.0037
    CVSS Score:5.4

    Affected Products

    Vendor
    Mintplexlabs
    Product
    Anythingllm

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High