T
he parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to read, write, and in certain configurations execute arbitrary files on the server by exploiting various endpoints. The vulnerability can be exploited even when the service is bound to localhost, through cross-site requests facilitated by malicious HTML/JS pages.
References
| Link | Resource |
|---|---|
| https://huntr.com/bounties/62b77589-772d-4d6e-aef4-2aec4cfe5f8b | Exploit Third Party Advisory |
| https://huntr.com/bounties/62b77589-772d-4d6e-aef4-2aec4cfe5f8b | Exploit Third Party Advisory |
Configurations
History
09 Jul 2025, 14:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lollms lollms Web Ui
Lollms |
|
| CPE | cpe:2.3:a:lollms:lollms_web_ui:9.0:*:*:*:*:*:*:* | |
| References | () https://huntr.com/bounties/62b77589-772d-4d6e-aef4-2aec4cfe5f8b - Exploit, Third Party Advisory |
21 Nov 2024, 08:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://huntr.com/bounties/62b77589-772d-4d6e-aef4-2aec4cfe5f8b - | |
| Summary |
|
Information
Published : 2024-04-10 17:15
Updated : 2025-07-09 14:08
NVD link : CVE-2024-1511
Mitre link : CVE-2024-1511
CVE.ORG link : CVE-2024-1511
JSON object : View
Products Affected
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')