CVE-2024-6281
CVSS V2 None
CVSS V3 None
Description
A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.
Overview
- CVE ID
- CVE-2024-6281
- Assigner
- @huntr_ai
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-20T03:19:25.663Z
- Last Modified Date
- 2024-07-20T03:19:25.663Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-6281 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6281 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-20 13:04:49 | Added to TrackCVE |