Back to Database
Status published
Medium
CVE-2024-8027
Stored Cross-Site Scripting (XSS) in netease-youdao/QAnything
Vulnerability Description
A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during user chats. This vulnerability affects all versions prior to the fix.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8027
Credits & Attribution
No credits recorded in the NVD database.
More from netease-youdao
View All →CVE-2024-8026
CSRF due to overly permissive CORS headers in netease-youdao/qanything
High
8.1
CVE-2024-8024
CORS Misconfiguration in netease-youdao/qanything
High
7.5
CVE-2024-7099
SQL Injection in netease-youdao/qanything
Critical
9.8
CVE-2024-12866
Local File Inclusion in netease-youdao/qanything
High
7.5
CVE-2024-12864
Unauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanything
High
7.5
Affected Vendor
netease-youdao
View all reports →Affected Software
netease-youdao/qanything
Vulnerable Versions:
unspecified
Timeline
Official Publish:
March 20th, 2025
Last Modified:
March 20th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N