Directory Listing Vulnerability in Parisneo Lollms-WebUI
CVE-2024-10047
5.3MEDIUM
What is CVE-2024-10047?
The Lollms-WebUI by Parisneo has a vulnerability that allows attackers to exploit the /open_file endpoint, enabling them to list arbitrary directories on Windows systems through specially crafted HTTP requests. This poses significant security risks, as unauthorized access to directory contents can lead to further exploitation. It is critical for users of Lollms-WebUI versions v9.9 and above to implement necessary mitigations to safeguard against potential attacks.
Affected Version(s)
parisneo/lollms-webui <= unspecified