Remote Code Execution Vulnerability in Parisneo/Lollms-Webui
CVE-2024-4326
9.8CRITICAL
What is CVE-2024-4326?
A vulnerability exists in Lollms-Webui by Parisneo, where insufficient protection of the /apply_settings and /execute_code endpoints permits remote attackers to execute arbitrary code. By modifying the host to localhost, attackers can bypass existing security measures, thereby disabling essential code validation through the /apply_settings endpoint. Following this, they can exploit the /execute_code endpoint to run arbitrary commands remotely due to a delay in the enforcement of settings. This significant security issue was remedied in version 9.5 to prevent unauthorized code execution.
Affected Version(s)
parisneo/lollms-webui < 9.5
