U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-6581

Change History

New CVE Received from huntr.dev 10/29/2024 9:15:07 AM

Action Type Old Value New Value
Added Description

								
							
							
						
A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, which in turn pose a risk of remote code execution. The sanitize_svg function only removes script elements and 'on*' event attributes, but does not account for other potential vectors for XSS within SVG files. This vulnerability can be exploited when authorized users access a malicious URL containing the crafted SVG file.
Added CVSS V3

								
							
							
						
huntr.dev AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Added CWE

								
							
							
						
huntr.dev CWE-79
Added Reference

								
							
							
						
huntr.dev https://github.com/parisneo/lollms/commit/328b960a0de2097e13654ac752253e9541521ddd [No types assigned]
Added Reference

								
							
							
						
huntr.dev https://huntr.com/bounties/ad68ecd6-44e2-449b-8e7e-f2b71b1b43c7 [No types assigned]