haotian-liu llava Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in haotian-liu/llava version 1.2.0 (LLaVA-1.6). This vulnerability allows an attacker to upload files containing malicious content without authentication or user interaction. The uploaded files are stored in a predictable location, which enables the execution of arbitrary JavaScript code in the context of the victim's browser when the crafted file URL is visited. Such exploitation could result in the theft of sensitive information, session hijacking, or other actions that compromise the victim's security and privacy.
Impact
Exploitation of this vulnerability could lead to unauthorized file uploads, allowing for the execution of malicious JavaScript in the victim's browser, with potential consequences such as information theft, session hijacking, or other privacy and security compromises.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
