Parisneo Lollms Vulnerable to Local File Inclusion Attacks
CVE-2024-4315
What is CVE-2024-4315?
The vulnerability in Lollms version 9.5, developed by Parisneo, arises from inadequate sanitization of file paths, specifically concerning Windows-style paths. The flaw in the sanitize_path_from_endpoint function permits attackers to exploit Local File Inclusion (LFI) attacks, resulting in the potential for directory traversal on Windows systems. This exploitation can take place through multiple endpoints, including personalities and /del_preset, granting unauthorized access to read or delete files within the Windows filesystem. As a consequence, this vulnerability poses significant risks to system integrity and availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parisneo/lollms < 9.8
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
