PT-2024-37735 · Lollms · Lollms

CVE-2024-6581

·

Published

2024-10-29

·

Updated

2024-11-01

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lollms version v9.9
Description A vulnerability in the discussion image upload function allows for the uploading of SVG files, which can lead to cross-site scripting (XSS) vulnerabilities and pose a risk of remote code execution. The sanitize svg function only removes script elements and on* event attributes, but does not account for other potential vectors for XSS within SVG files. This issue can be exploited when authorized users access a malicious URL containing the crafted SVG file.
Recommendations For version v9.9, consider disabling the sanitize svg function or restricting the upload of SVG files until a patch is available. As a temporary workaround, restrict access to the discussion image upload function to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6581
GHSA-CM59-8RMV-F2CJ
PYSEC-2024-116

Affected Products

Lollms