VYPR
Medium severity6.1NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026

CVE-2024-1602

CVE-2024-1602

Description

parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the /execute_code endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Lollms/Lollms3 versions
    cpe:2.3:a:lollms:lollms_web_ui:9.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:lollms:lollms_web_ui:9.0:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.