ZeroHour

CVE-2024-7044

PoC
CVSS 3.1
8.9 high
EPSS
<1%p42
Published
()
Modified
Description

A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.

Vendors
openwebui
Products
open webui
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.