CVE-2024-5824

A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as `force_accept_remote_access` and `turn_on_code_validation`.
Configurations

No configuration.

History

No history.

Information

Published : 2024-06-27 19:15

Updated : 2024-06-27 19:25


NVD link : CVE-2024-5824

Mitre link : CVE-2024-5824

CVE.ORG link : CVE-2024-5824


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')