PT-2024-38022 · Unknown · Parisneo/Lollms-Webui+1
Published
2024-10-11
·
Updated
2024-11-15
·
CVE-2024-6985
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
parisneo/lollms-webui (affected versions not specified)
parisneo/lollms (affected versions not specified)
Description
A path traversal issue exists due to improper sanitization of the
personality folder parameter in the "api open personality folder" endpoint. This allows an attacker to read any folder in the personality folder on the victim's computer and access arbitrary files, despite sanitize path being set.Recommendations
For parisneo/lollms-webui, as a temporary workaround, consider restricting access to the "api open personality folder" endpoint until a patch is available.
For parisneo/lollms, avoid using the
personality folder parameter in the affected endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parisneo/Lollms
Parisneo/Lollms-Webui