Unauthorized Directory Deletion Vulnerability in parisneo/lollms-webui
CVE-2024-9919
8.4HIGH
What is CVE-2024-9919?
A security issue in parisneo/lollms-webui V13 stems from a missing authentication verification in its API's uninstall endpoint. This flaw allows unauthorized users to delete directories by accessing the /uninstall/{app_name} endpoint without proper authentication. The absence of a call to the check_access() function for client validation poses a serious risk, enabling malicious actors to manipulate the application's directory structures without any authentication checks in place.
Affected Version(s)
parisneo/lollms-webui <= unspecified