A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the `/apply_settings` endpoint. Subsequently, arbitrary commands can be executed remotely via the `/execute_code` endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-16 09:15
Updated : 2024-05-16 13:03
NVD link : CVE-2024-4326
Mitre link : CVE-2024-4326
CVE.ORG link : CVE-2024-4326
JSON object : View
Products Affected
No product.
CWE
CWE-15
External Control of System or Configuration Setting