Vulnerability Description
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lollms | Lollms-Webui | 9.6 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/740dda3e-7104-4ccf-9ac4-8870e4d6d602ExploitThird Party Advisory
- https://huntr.com/bounties/740dda3e-7104-4ccf-9ac4-8870e4d6d602ExploitThird Party Advisory
FAQ
What is CVE-2024-4841?
CVE-2024-4841 is a vulnerability with a CVSS score of 3.3 (LOW). A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects ver...
How severe is CVE-2024-4841?
CVE-2024-4841 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4841?
Check the references section above for vendor advisories and patch information. Affected products include: Lollms Lollms-Webui.