CVE-2024-7044: Stored XSS in open-webui/open-webui
A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7044?
CVE-2024-7044 is classified as a critical severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2024-7044?
To fix CVE-2024-7044, upgrade your open-webui version to a later release that addresses this vulnerability.
What environments are affected by CVE-2024-7044?
CVE-2024-7044 affects open-webui version 0.3.8 and earlier, including all installations using this version.
What type of attack does CVE-2024-7044 enable?
CVE-2024-7044 enables stored cross-site scripting (XSS) attacks by allowing attackers to inject malicious JavaScript into uploaded files.
What can attackers do with CVE-2024-7044?
Attackers exploiting CVE-2024-7044 can execute JavaScript in the context of a victim's session, leading to data theft or other malicious actions.