A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By crafting a malicious HTTP request, an attacker can traverse the directory structure and view the contents of any folder, albeit limited to subfolder names only. This issue was demonstrated via a specific HTTP request that manipulated the 'category' parameter to access arbitrary directories. The vulnerability is present in the code located at the 'endpoints/lollms_advanced.py' file.
References
Configurations
No configuration.
History
30 May 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-30 15:15
Updated : 2024-05-30 18:19
NVD link : CVE-2024-4330
Mitre link : CVE-2024-4330
CVE.ORG link : CVE-2024-4330
JSON object : View
Products Affected
No product.
CWE
CWE-23
Relative Path Traversal