Stored Cross-Site Scripting Vulnerability in Netease Youdao QAnything
CVE-2024-8027
6.1MEDIUM
What is CVE-2024-8027?
A stored Cross-Site Scripting (XSS) vulnerability has been identified in Netease Youdao's QAnything product. This security issue allows attackers to upload harmful knowledge files that can execute XSS attacks during user interactions, potentially compromising user data and security. All versions prior to the release of the fix are susceptible to this vulnerability, necessitating immediate attention from users to secure their chat functionalities.
Affected Version(s)
netease-youdao/qanything <= unspecified
