Serge Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in Serge version 0.9.0. This issue arises from inadequate sanitization of input during web page generation in the chat prompt. An attacker can exploit this vulnerability by sending a message that includes malicious HTML or JavaScript. This crafted message is stored and executed whenever the chat is accessed, potentially displaying unintended content to the user and facilitating phishing attacks.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the chat.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
