A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized access to arbitrary files on the server, potentially exposing sensitive information such as private SSH keys, configuration files, and source code.
References
Configurations
No configuration.
History
30 Sep 2024, 12:45
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
30 Sep 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-30 08:15
Updated : 2024-09-30 12:45
NVD link : CVE-2024-6394
Mitre link : CVE-2024-6394
CVE.ORG link : CVE-2024-6394
JSON object : View
Products Affected
No product.
CWE
CWE-29
Path Traversal: '\..\filename'