PT-2024-31349 · Lollms+1 · Lollms+2

Published

2024-06-24

·

Updated

2024-09-13

·

CVE-2024-4499

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions lollms version 9.6
Description A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server due to a lax CORS policy, allowing attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage. This can trigger arbitrary LoLLMS-XTTS API requests, leading to the reading and writing of audio files. When combined with other vulnerabilities, it could allow for the reading of arbitrary files on the system and writing files outside the permitted audio file location.
Recommendations For version 9.6, consider implementing a stricter CORS policy to prevent unauthorized API requests as a temporary workaround. Restrict access to the XTTS server to minimize the risk of exploitation. Avoid using the LoLLMS-XTTS API for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-4499

Affected Products

Lollms-Xtts Api
Xtts Server
Lollms