CVE-2024-6281

CVSS V2 None CVSS V3 None
Description
A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.
Overview
  • CVE ID
  • CVE-2024-6281
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-20T03:19:25.663Z
  • Last Modified Date
  • 2024-07-20T03:19:25.663Z
History
Created Old Value New Value Data Type Notes
2024-07-20 13:04:49 Added to TrackCVE