Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4499

Опубликовано: 24 июн. 2024
Источник: nvd
CVSS3: 7.6
CVSS3: 6.3
EPSS Низкий

Описание

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage, which can then trigger arbitrary LoLLMS-XTTS API requests. This issue can lead to the reading and writing of audio files and, when combined with other vulnerabilities, could allow for the reading of arbitrary files on the system and writing files outside the permitted audio file location.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lollms:lollms:9.6:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00095
Низкий

7.6 High

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.6
github
больше 1 года назад

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage, which can then trigger arbitrary LoLLMS-XTTS API requests. This issue can lead to the reading and writing of audio files and, when combined with other vulnerabilities, could allow for the reading of arbitrary files on the system and writing files outside the permitted audio file location.

EPSS

Процентиль: 27%
0.00095
Низкий

7.6 High

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-352