Логотип exploitDog
bind:CVE-2024-9919
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9919

Количество 2

Количество 2

nvd логотип

CVE-2024-9919

11 месяцев назад

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-6w2c-f4vg-j9hv

11 месяцев назад

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-9919

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.

CVSS3: 8.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-6w2c-f4vg-j9hv

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.

CVSS3: 8.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу