CVE-2024-5711 Cross site scripting

Remediate Within 6 Months

A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inject malicious payloads into the chat input. This vulnerability is due to the lack of input validation and sanitization on both the frontend and backend components of the application. Specifically, the application fails to sanitize user input in the chat feature, leading to the execution of arbitrary JavaScript code in the context of the user's browser session. This issue affects all versions of the application. The impact of this vulnerability includes the potential for stolen credentials, extraction of sensitive information from chat logs, projects, and other data accessible through the application.

Stitionai - (1)

Cross site scripting

Vulnerability weakness type is in the top 25 CWEs according to MITRE. View Mitre Top 25 CWEs


No exploit code is reported to exist.

Active Exploitation

Vulnerability is not in CISA's Known Exploited Vulnerabilities (KEV) catalog. See the KEV Catalog

Threat Actor Activity

No sightings of the vulnerability within threat reports.

T1591 - Gather Victim Org Information
T1590 - Gather Victim Network Information
T1589.001 - Gather Victim Identity Information (Credentials)
T1566.002 - Phishing (Spearphishing Link)
T1566 - Phishing
T1552 - Unsecured Credentials
T1539 - Steal Web Session Cookie
T1499.004 - Endpoint Denial of Service (Application or System Exploitation)
T1190 - Exploit Public-Facing Application
T1189 - Drive-by Compromise
T1082 - System Information Discovery
T1078 - Valid Accounts
T1059 - Command and Scripting Interpreter
T1021 - Remote Services
T1003 - OS Credential Dumping

PCI DSS v3.2.1-6.5.8 - Improper Access Control
PCI DSS v3.2.1-6.5.7 - Cross Site Scripting
PCI DSS v3.2.1-6.5.5 - Improper Error Handling

WASC-8 - Cross Site Scripting