PT-2024-18193 · Unknown · Parisneo/Lollms-Webui

Published

2024-04-15

·

Updated

2025-07-07

·

CVE-2024-1646

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui (affected versions not specified)
Description The issue is related to insufficient protection over sensitive endpoints, allowing for authentication bypass. The application's restriction method, which checks if the host parameter is not '0.0.0.0', is inadequate when the application is bound to a specific interface. This vulnerability can lead to denial of service, unauthorized disabling or overriding of recordings, and potentially other impacts if certain features are enabled in the configuration. Sensitive endpoints include '/restart program', '/update software', '/check update', '/start recording', and '/stop recording'.
Recommendations As a temporary workaround, consider restricting access to the sensitive endpoints '/restart program', '/update software', '/check update', '/start recording', and '/stop recording' to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-1646

Affected Products

Parisneo/Lollms-Webui