CVE-2024-6986

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations.
References
Link Resource
https://huntr.com/bounties/83e9bde1-40b2-49e9-be1c-bc1498eb8ebd Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:lollms:lollms_web_ui:9.8:*:*:*:*:*:*:*

History

08 Jul 2025, 16:14

Type Values Removed Values Added
CPE cpe:2.3:a:lollms:lollms_web_ui:9.8:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 5.4
References () https://huntr.com/bounties/83e9bde1-40b2-49e9-be1c-bc1498eb8ebd - () https://huntr.com/bounties/83e9bde1-40b2-49e9-be1c-bc1498eb8ebd - Exploit, Third Party Advisory
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) en la página de configuración de parisneo/lollms-webui versión 9.8. Esta vulnerabilidad se debe al uso indebido de la directiva "v-html", que inserta el contenido de la variable "full_template" directamente como HTML. Esto permite a un atacante ejecutar código JavaScript malicioso inyectando un payload en el campo de entrada "Plantilla del sistema" en las configuraciones principales.
First Time Lollms
Lollms lollms Web Ui

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-08 16:14


NVD link : CVE-2024-6986

Mitre link : CVE-2024-6986

CVE.ORG link : CVE-2024-6986


JSON object : View

Products Affected

lollms

  • lollms_web_ui
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')