Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3851

Опубликовано: 16 мая 2024
Источник: nvd
CVSS3: 6.8
CVSS3: 5.4
EPSS Низкий

Описание

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pribai:privategpt:*:*:*:*:*:*:*:*
Версия до 0.6.2 (включая)

EPSS

Процентиль: 50%
0.00267
Низкий

6.8 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.8
github
больше 1 года назад

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository.

EPSS

Процентиль: 50%
0.00267
Низкий

6.8 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79