Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-43854

Опубликовано: 28 апр. 2025
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:*
Версия до 0.6.8 (включая)

EPSS

Процентиль: 13%
0.00044
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021

EPSS

Процентиль: 13%
0.00044
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021