Логотип exploitDog
bind:CVE-2024-6139
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6139

Количество 2

Количество 2

nvd логотип

CVE-2024-6139

больше 1 года назад

A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-w9qf-83jg-2x6c

больше 1 года назад

lollms vulnerable to dot-dot-slash path traversal in XTTS server

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-6139

A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-w9qf-83jg-2x6c

lollms vulnerable to dot-dot-slash path traversal in XTTS server

CVSS3: 7.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу