Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6959

Опубликовано: 13 окт. 2024
Источник: nvd
CVSS3: 7.1
CVSS3: 7.1
EPSS Низкий

Описание

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lollms:lollms_web_ui:9.8:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.0013
Низкий

7.1 High

CVSS3

7.1 High

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 7.1
github
больше 1 года назад

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

EPSS

Процентиль: 33%
0.0013
Низкий

7.1 High

CVSS3

7.1 High

CVSS3

Дефекты

CWE-352
CWE-352