Vulnerability Description
In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding, /reinstall_binding, /unInstall_binding, /set_active_binding_settings, and /update_binding_settings are susceptible to CSRF attacks and local attacks. An attacker can exploit this vulnerability to perform unauthorized actions on the victim's machine.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lollms | Lollms Web Ui | 9.8 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/ac0bbb1d-89aa-42ba-bc48-1b59bd16acc7ExploitThird Party Advisory
FAQ
What is CVE-2024-6040?
CVE-2024-6040 is a vulnerability with a CVSS score of 8.8 (HIGH). In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /inst...
How severe is CVE-2024-6040?
CVE-2024-6040 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6040?
Check the references section above for vendor advisories and patch information. Affected products include: Lollms Lollms Web Ui.