Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qxp-588w-rmqg

Опубликовано: 29 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

EPSS

Процентиль: 37%
0.00154
Низкий

8.1 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 7.1
nvd
больше 1 года назад

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

EPSS

Процентиль: 37%
0.00154
Низкий

8.1 High

CVSS3

Дефекты

CWE-346