CVE Feed

    Dashboard / CVE / CVE-2024-6581

    CVE-2024-6581

    A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, which in turn pose a risk of remote code execution. The sanitize_svg function only removes script elements and 'on*' event attributes, but does not account for other potential vectors for XSS within SVG files. This vulnerability can be exploited when authorized users access a malicious URL containing the crafted SVG file.

    Published:Oct 29, 2024
    Last Modified:Nov 1, 2024
    EPS:Oct 29, 2024
    EPSS Score:0.00475
    CVSS Score:9

    Affected Products

    Vendor
    Lollms
    Product
    Lord Of Large Language Models
    Vendor
    Parisneo
    Product
    Lollms

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High