Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4326

Опубликовано: 16 мая 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the /apply_settings and /execute_code endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the /apply_settings endpoint. Subsequently, arbitrary commands can be executed remotely via the /execute_code endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*
Версия до 9.5 (исключая)

EPSS

Процентиль: 78%
0.01133
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-15

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the `/apply_settings` endpoint. Subsequently, arbitrary commands can be executed remotely via the `/execute_code` endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.

EPSS

Процентиль: 78%
0.01133
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-15