Vulnerability Description
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lollms | Lollms Web Ui | 13 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/5c00f56b-32a8-4e26-a4e3-de64f139da6bExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2024-9919?
CVE-2024-9919 is a vulnerability with a CVSS score of 8.4 (HIGH). A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call...
How severe is CVE-2024-9919?
CVE-2024-9919 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9919?
Check the references section above for vendor advisories and patch information. Affected products include: Lollms Lollms Web Ui.