CVE-2024-5711
Last modified
CVE-2024-5711 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inject malicious payloads into the chat input. This vulnerability is due to the lack of input validation and sanitization on both the frontend and backend components of the application. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inject malicious payloads into the chat input. This vulnerability is due to the lack of input validation and sanitization on both the frontend and backend components of the application. Specifically, the application fails to sanitize user input in the chat feature, leading to the execution of arbitrary JavaScript code in the context of the user's browser session. This issue affects all versions of the application. The impact of this vulnerability includes the potential for stolen credentials, extraction of sensitive information from chat logs, projects, and other data accessible through the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stitionai | Devika | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5711?
How severe is CVE-2024-5711?
How do I fix CVE-2024-5711?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-57095SQL injection vulnerability in Go-CMS v.1.1.10 allows a remo…6.8
- CVE-2024-57096An issue in wps office before v.19302 allows a local attacke…5.5
- CVE-2024-57097ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in …4.8
- CVE-2024-57098Moss v0.1.3 version has an SQL injection vulnerability that …9.8
- CVE-2024-57099ClassCMS v4.8 has a code execution vulnerability. Attackers …9.8
- CVE-2024-5710berriai/litellm version 1.34.34 is vulnerable to improper ac…6.5
- CVE-2024-5712A Cross-Site Request Forgery (CSRF) vulnerability was identi…8.1
- CVE-2024-5713The If-So Dynamic Content Personalization WordPress plugin b…5.4
- CVE-2024-5714In lunary-ai/lunary version 1.2.4, an improper access contro…6.8
- CVE-2024-5715The wp-eMember WordPress plugin before 10.6.7 does not sanit…7.1
- CVE-2024-57151SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and b…6.8
- CVE-2024-57152Incorrect access control in the preHandle function of my-sit…7.5
Are you affected by CVE-2024-5711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
