CVE-2024-45989 - CERT CVE
ID CVE-2024-45989
Sažetak Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server.
Reference
CVSS
Base: 4.0
Impact: 1.4
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Zadnje važnije ažuriranje 30-09-2024 - 12:46
Objavljeno 26-09-2024 - 18:15