THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-2361

Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webui

Reserved:2024-03-10
Published:2024-05-16
Updated:2024-05-16

Description

A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where the application fails to properly sanitize the `file://` protocol and other inputs, leading to arbitrary read and upload capabilities. Attackers can exploit this vulnerability by manipulating the `path` and `variant_name` parameters to achieve path traversal, allowing for the reading of arbitrary files and uploading files to arbitrary locations on the server. This vulnerability affects the latest version of parisneo/lollms-webui.



CRITICAL: 9.6CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-29 Path Traversal: '\..\filename'

Product status

Any version
affected

References

https://huntr.com/bounties/cd383817-924a-445a-838e-d0c867c6a176

cve.org CVE-2024-2361

nvd.nist.gov CVE-2024-2361

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-2361