Описание
A vulnerability in the upload_app function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the filename value, causing a Path Traversal error.
Ссылки
- Patch
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:lollms:lollms_web_ui:12:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00223
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 9.1
github
11 месяцев назад
A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.
EPSS
Процентиль: 45%
0.00223
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-22