CVE Feed

    Dashboard / CVE / CVE-2024-1602

    CVE-2024-1602

    parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the `/execute_code` endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.

    Published:Apr 10, 2024
    Last Modified:Jul 9, 2025
    EPS:Apr 10, 2024
    EPSS Score:0.00181
    CVSS Score:6.1

    Affected Products

    Vendor
    Lollms
    Product
    Lollms Web Ui

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High