CSRF Vulnerability in clear_personality_files_list Function
CVE-2024-4328
8.1HIGH
What is CVE-2024-4328?
A vulnerability exists in the clear_personality_files_list function of the Lollms Web UI, specifically in version 9.6, that allows for Cross-Site Request Forgery (CSRF) attacks. This vulnerability is due to the usage of a GET request which fails to implement adequate CSRF protection mechanisms. As a result, attackers can exploit this flaw to trick users into executing unwanted actions, potentially leading to the deletion of critical personality files without proper authorization.
Affected Version(s)
parisneo/lollms-webui <= unspecified