PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2024-31839

4.8
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
chaos
Updated Sep 18, 2026View on NVD →
S4E scanner
mediumWeb Vulnerabilities~10 seconds

CHAOS 5.0.1 'sendCommandHandler' - Cross-Site Scripting

Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component. References: https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/chaos_rat_xss_to_rce.rb https://github.com/tiagorlampert/CHAOS

Used 2.4k times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →