PT-2024-18110 · Unknown · Lollms-Webui

Published

2024-03-30

·

Updated

2024-04-16

·

CVE-2024-1522

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions lollms-webui (affected versions not specified)
Description A Cross-Site Request Forgery (CSRF) issue in the lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The issue stems from the "/execute code" API endpoint, which does not properly validate requests. This enables an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands, allowing attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-1522

Affected Products

Lollms-Webui