Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 PyPI

Lollms vulnerable to Cross-site Scripting

GHSA-cm59-8rmv-f2cj · CVE-2024-6581 · PYSEC-2024-116

Published · Modified

Description

A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, which in turn pose a risk of remote code execution. The sanitize_svg function only removes script elements and 'on*' event attributes, but does not account for other potential vectors for XSS within SVG files. This vulnerability can be exploited when authorized users access a malicious URL containing the crafted SVG file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes