PT-2024-37791 · Unknown · Lollms-Webui
Published
2024-10-29
·
Updated
2024-11-02
·
CVE-2024-6674
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
lollms-webui versions prior to 10
Description
A CORS misconfiguration allows attackers to steal sensitive information, such as logs, browser sessions, and settings containing private API keys from other services. This issue can also enable attackers to perform actions on behalf of a user, including deleting a project or sending a message, impacting the confidentiality and integrity of the information.
Recommendations
For versions prior to 10, update to version 10 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to prevent unauthorized actions on behalf of a user.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms-Webui