PT-2025-12238 · Unknown · Parisneo/Lollms-Webui

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-8581

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui version V12 (Strawberry)
Description The issue concerns a function named upload app that does not properly filter user input for the filename value, leading to a Path Traversal error. This allows an attacker to delete any file or directory on the system.
Recommendations For parisneo/lollms-webui version V12 (Strawberry), consider disabling the upload app function until a patch is available to prevent potential exploitation. Restrict access to sensitive files and directories to minimize the risk of deletion.

Exploit

Fix

Path traversal

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8581

Affected Products

Parisneo/Lollms-Webui