PT-2024-18110 · Unknown · Lollms-Webui
Published
2024-03-30
·
Updated
2024-04-16
·
CVE-2024-1522
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
lollms-webui (affected versions not specified)
Description
A Cross-Site Request Forgery (CSRF) issue in the lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The issue stems from the "/execute code" API endpoint, which does not properly validate requests. This enables an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands, allowing attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms-Webui