Remote Code Execution Vulnerability in Lollms-Webui
CVE-2024-2366

9CRITICAL

Key Information:

Vendor

Parisneo

Vendor
CVE Published:
16 May 2024

What is CVE-2024-2366?

A vulnerability exists within the parisneo/lollms-webui application that allows for remote code execution through improper path sanitization in the reinstall_binding functionality. The issue is located in the lollms_core module, specifically in the lollms/server/endpoints/lollms_binding_infos.py script. Attackers can exploit this vulnerability by manipulating the binding_path variable, enabling them to direct the application to unintended directories. By uploading a crafted init.py file to a controlled directory, an attacker could gain the capability to execute arbitrary code, posing significant risks to the integrity and security of the server.

Affected Version(s)

parisneo/lollms-webui <= unspecified

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.