PT-2024-37998 · Parisneo · Lollms-Webui

Published

2024-10-13

·

Updated

2024-11-03

·

CVE-2024-6959

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui version 9.8
Description A Denial of Service (DOS) attack can be performed when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The issue leads to service disruption, resource exhaustion, and extended downtime.
Recommendations As a temporary workaround, consider disabling the audio file upload feature until a patch is available. Restrict access to the multipart boundary to minimize the risk of exploitation. Upgrade to a patched version immediately to mitigate the risk.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-6959

Affected Products

Lollms-Webui