Description
A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.
INFO
Published Date :
2024-05-16T09:03:48.687Z
Last Modified :
2024-08-01T20:12:07.326Z
Source :
@huntr_ai
AFFECTED PRODUCTS
The following products are affected by CVE-2024-3435 vulnerability.
| Vendors | Products |
|---|---|
| Lollms |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-3435.