CVE-2024-6986 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the…
Medium CVSS: 5.4

CVE-2024-6986

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations.
Vendor
Lollms
Product
Lollms Web Ui
CWE
CWE-79
Yayın Tarihi
2025-03-20 10:15:34
Güncelleme
2025-07-08 16:14:33
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar