Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6674

Опубликовано: 29 окт. 2024
Источник: nvd
CVSS3: 8.1
CVSS3: 7.1
EPSS Низкий

Описание

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*
Версия до 10 (исключая)

EPSS

Процентиль: 36%
0.00154
Низкий

8.1 High

CVSS3

7.1 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 8.1
github
больше 1 года назад

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.

EPSS

Процентиль: 36%
0.00154
Низкий

8.1 High

CVSS3

7.1 High

CVSS3

Дефекты

CWE-346