PT-2024-19052 · Unknown · Parisneo/Lollms-Webui

Published

2024-06-02

·

Updated

2024-06-03

·

CVE-2024-2178

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui (affected versions not specified)
Description A path traversal issue exists, specifically within the "copy to custom personas" endpoint in the "lollms personalities infos.py" file. This issue allows attackers to read arbitrary files by manipulating the category and name parameters during the "Copy to custom personas folder for editing" process. By inserting '../' sequences in these parameters, attackers can traverse the directory structure and access files outside of the intended directory. Successful exploitation results in unauthorized access to sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2178

Affected Products

Parisneo/Lollms-Webui