Unauthorized Directory Deletion Vulnerability in parisneo/lollms-webui
CVE-2024-9919
8.4HIGH
Summary
A security issue in parisneo/lollms-webui V13 stems from a missing authentication verification in its API's uninstall endpoint. This flaw allows unauthorized users to delete directories by accessing the /uninstall/{app_name} endpoint without proper authentication. The absence of a call to the check_access() function for client validation poses a serious risk, enabling malicious actors to manipulate the application's directory structures without any authentication checks in place.
Affected Version(s)
parisneo/lollms-webui <= unspecified
References
CVSS V3.0
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved