PT-2024-37998 · Parisneo · Lollms-Webui
Published
2024-10-13
·
Updated
2024-11-03
·
CVE-2024-6959
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
parisneo/lollms-webui version 9.8
Description
A Denial of Service (DOS) attack can be performed when uploading an audio file. If an attacker appends a large number of characters to the end of a
multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The issue leads to service disruption, resource exhaustion, and extended downtime.Recommendations
As a temporary workaround, consider disabling the audio file upload feature until a patch is available.
Restrict access to the multipart boundary to minimize the risk of exploitation.
Upgrade to a patched version immediately to mitigate the risk.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms-Webui