Parisneo Lollms Path Traversal Vulnerability
CVE-2024-6281
7.3HIGH
Key Information
- Vendor
- Parisneo
- Status
- Parisneo/lollms
- Vendor
- CVE Published:
- 20 July 2024
Summary
A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.
Affected Version(s)
parisneo/lollms < 9.5.1
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 7.3 - (HIGH)
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database