Remote Code Execution Vulnerability in Parisneo/Lollms-Webui
CVE-2024-4326
9.8CRITICAL
What is CVE-2024-4326?
A vulnerability exists in Lollms-Webui by Parisneo, where insufficient protection of the /apply_settings
and /execute_code
endpoints permits remote attackers to execute arbitrary code. By modifying the host to localhost, attackers can bypass existing security measures, thereby disabling essential code validation through the /apply_settings
endpoint. Following this, they can exploit the /execute_code
endpoint to run arbitrary commands remotely due to a delay in the enforcement of settings. This significant security issue was remedied in version 9.5 to prevent unauthorized code execution.
Affected Version(s)
parisneo/lollms-webui < 9.5