Netease Youdao QAnything Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Netease Youdao QAnything, affecting all versions prior to the fix. This vulnerability allows attackers to upload malicious knowledge files to the knowledge base, which can then trigger XSS attacks during user chats.

Impact

Exploitation of this vulnerability allows for the execution of malicious JavaScript code in the context of the user's browser, potentially leading to hijacking the victim's browser session.

Reproduction

To reproduce this vulnerability, first upload a file containing malicious JavaScript into the document collection of a created knowledge base. Then, engage in a conversation with the QAnything service, which will trigger the XSS attack by executing the uploaded JavaScript.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.