CVE detail
CVE-2024-12871 — CVE-2024-12871
Published 2025-03-20 · Modified 2026-06-17 · Vendor infiniflow · Product ragflow · Source nvd
MEDIUM
severity
CVSS-derived band
0.0037
EPSS probability
exploitation probability, 30d
29.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the user's browser. This can lead to session hijacking, data exfiltration, or unauthorized actions performed on behalf of the victim, compromising sensitive user data and affecting the integrity of the entire application.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References