CVE-2024-8898

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lollms:lollms_web_ui:12:*:*:*:*:*:*:*

History

01 Apr 2025, 20:30

Type Values Removed Values Added
First Time Lollms lollms Web Ui
Lollms
CPE cpe:2.3:a:lollms:lollms_web_ui:12:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 9.8
References () https://github.com/parisneo/lollms-webui/commit/6d07c8a0dd0a15cc060becc73fda9fe8e788eb23 - () https://github.com/parisneo/lollms-webui/commit/6d07c8a0dd0a15cc060becc73fda9fe8e788eb23 - Patch
References () https://huntr.com/bounties/6072371f-0ddc-42e3-9207-1c6d6b18d32f - () https://huntr.com/bounties/6072371f-0ddc-42e3-9207-1c6d6b18d32f - Exploit

20 Mar 2025, 17:15

Type Values Removed Values Added
References () https://huntr.com/bounties/6072371f-0ddc-42e3-9207-1c6d6b18d32f - () https://huntr.com/bounties/6072371f-0ddc-42e3-9207-1c6d6b18d32f -
Summary
  • (es) Existe una vulnerabilidad de path traversal en los endpoints de la API de instalación y desinstalación de parisneo/lollms-webui versión V12 (Strawberry). Esta vulnerabilidad permite a los atacantes crear o eliminar directorios con rutas arbitrarias en el sistema. El problema surge debido a una depuración insuficiente de la entrada del usuario, lo cual puede explotarse para navegar por directorios fuera de la ruta deseada.

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-04-01 20:30


NVD link : CVE-2024-8898

Mitre link : CVE-2024-8898

CVE.ORG link : CVE-2024-8898


JSON object : View

Products Affected

lollms

  • lollms_web_ui
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')