CVE-2024-4315
CVSS V2 None
CVSS V3 None
Description
parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory traversal attacks on Windows systems. This vulnerability can be exploited through various routes, including `personalities` and `/del_preset`, to read or delete any file on the Windows filesystem, compromising the system's availability.
Overview
- CVE ID
- CVE-2024-4315
- Assigner
- @huntr_ai
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-12T00:40:15.768Z
- Last Modified Date
- 2024-06-12T00:40:15.768Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-4315 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4315 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-23 22:33:53 | Added to TrackCVE |