PT-2024-37791 · Unknown · Lollms-Webui

Published

2024-10-29

·

Updated

2024-11-02

·

CVE-2024-6674

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions lollms-webui versions prior to 10
Description A CORS misconfiguration allows attackers to steal sensitive information, such as logs, browser sessions, and settings containing private API keys from other services. This issue can also enable attackers to perform actions on behalf of a user, including deleting a project or sending a message, impacting the confidentiality and integrity of the information.
Recommendations For versions prior to 10, update to version 10 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to prevent unauthorized actions on behalf of a user.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2024-6674

Affected Products

Lollms-Webui