CVE-2024-8027

A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during user chats. This vulnerability affects all versions prior to the fix.
References
Link Resource
https://huntr.com/bounties/cf75f024-3d64-416d-adfe-c4255d7c3f34 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:youdao:qanything:*:*:*:*:*:*:*:*

History

01 Aug 2025, 01:46

Type Values Removed Values Added
First Time Youdao qanything
Youdao
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en netease-youdao/QAnything. Los atacantes pueden subir archivos de conocimiento maliciosos a la base de conocimientos, lo que puede desencadenar ataques XSS durante los chats de los usuarios. Esta vulnerabilidad afecta a todas las versiones anteriores a la corrección.
References () https://huntr.com/bounties/cf75f024-3d64-416d-adfe-c4255d7c3f34 - () https://huntr.com/bounties/cf75f024-3d64-416d-adfe-c4255d7c3f34 - Exploit, Third Party Advisory
CPE cpe:2.3:a:youdao:qanything:*:*:*:*:*:*:*:*

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 01:46


NVD link : CVE-2024-8027

Mitre link : CVE-2024-8027

CVE.ORG link : CVE-2024-8027


JSON object : View

Products Affected

youdao

  • qanything
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')